[squid-users] Question squid on centos 6.5 and poodle

2014-10-16 Thread Alexander Samad
Hi I am trying to reconfig the ssl setup on a reverse proxy set https_port 2.7.3.1:443 accel cert=/etc/httpd/conf.d/office.xyz.com.crt key=/etc/httpd/conf.d/office.xyz.com.key dhparams=/etc/httpd/conf.d/office.xyz.com.dhparam defaultsite=office.yieldbroker.com options=NO_SSLv2,NO_SSLv3 cipher=AL

Re: [squid-users] Question squid on centos 6.5 and poodle

2014-10-17 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 17/10/2014 7:24 p.m., Alexander Samad wrote: > Hi > > I am trying to reconfig the ssl setup on a reverse proxy set > > https_port 2.7.3.1:443 accel > cert=/etc/httpd/conf.d/office.xyz.com.crt > key=/etc/httpd/conf.d/office.xyz.com.key > dhparams

Re: [squid-users] Question squid on centos 6.5 and poodle

2014-10-19 Thread Alexander Samad
Hi Thanks for clearing that up. so when i do a openssl ciphers and select the ciphers i want including the PFS enables oned, i take the list and try and use it in ciphers= and the list seems to be dissregarded and only 1 cipher is available. atleast from online checking and with nmap. I have noss

Re: [squid-users] Question squid on centos 6.5 and poodle

2014-10-19 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 20/10/2014 2:28 p.m., Alexander Samad wrote: > Hi > > Thanks for clearing that up. so when i do a openssl ciphers and > select the ciphers i want including the PFS enables oned, i take > the list and try and use it in ciphers= and the list seems to

Re: [squid-users] Question squid on centos 6.5 and poodle

2014-10-19 Thread Alexander Samad
Hi Hmm thats strange as its openssl that is giving me the list ... openssl ciphers 'ALL:!SSLv2:!SSLv3:@STRENGTH' plus when i don't put anything in the ciphers option I get most (but not all of the ciphers). A On 20 October 2014 12:36, Amos Jeffries wrote: > -BEGIN PGP SIGNED MESSAGE- >