Re: [users@httpd] Enabling Forward secrecy on SSL

2017-03-17 Thread David Mehler
Hello, Try this configuration. If anyone can take a look at this setup if I've missed something or need to get a protocol adjustment let me know. I get an A+ on ssllabs. Hth Dave. httpd-ssl.conf: SSLRandomSeed startup file:/dev/urandom 512 SSLRandomSeed connect file:/dev/urandom 512 # OCSP Stap

[users@httpd] Enabling Forward secrecy on SSL

2017-03-17 Thread Chunduru, Krishnachaithanya
Hi All, Can someone advise me on how to achieve the below on a server running with Apache SSL enabled. * SSL - Supports Weak Encryption The following protocols should be switched on - TLS 1.2, TLS 1.1, TLS 1.0. SSL 3 and SSL 2 should be disabled. * Weak Configuration - SSL/TL