On Tue, Aug 18, 2009 at 10:36 AM,
Capstone<capst...@capstone-solutions.net> wrote:
> I may not have been clear on my question so I am reposting, hopefully in a
> more clear manner,... I apologize if this is bad practice.
>
> I would like clarification as to whether the SSLProtocol directive is
> absolutely necessary when trying to achieve the highest level of security
> when configuring Apache.
>
> Can the SSLCipherSuite directive overwrite what is designated in the
> SSLProtocol directive?
>
> For example:
>
> SSLProtocol SSLv2
>
> SSLCipherSuite TLSv1:SSLv3:+HIGH:+MEDIUM:!LOW:!NULL

Try it and see?

-- 
Eric Covener
cove...@gmail.com

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org
   "   from the digest: users-digest-unsubscr...@httpd.apache.org
For additional commands, e-mail: users-h...@httpd.apache.org

Reply via email to