Welcome! Log In Create A New Profile

Advanced

SSL ciphers preference

B.R.
September 01, 2014 10:58AM
Hello,

I filled a (now closed, because erroneous) enhancement ticket:
http://trac.nginx.org/nginx/ticket/619

As it appears, the change I noticed in the SSl test did not result from my
malformed ciphers list.
Right about that.

However, what is intriguing is the answer Maxim gave me on the second part
of my proposal: the default activation of ssl_prefer_server_ciphers
<http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_prefer_server_ciphers>
..

He saif that this option put to on made sense with a custome list but not
with the default one.

I confirm that the results of my tests changed. It was no because of the
ciphers list, but it was due to that other change.
Thus, the ciphers used by the emulated clients of the test changed
following the activation of that option, allowing me to pass the 'Forward
Secrecy' part of the test, resulting in an upgrade of my score from A- to A.

I jsut checked it again, removing my buggy ciphers list and (de)activating
de rprefer' option.

If using that option with the default ciphers list was useless, what had
that change an impact on the results of my test?
---
*B. R.*
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

SSL ciphers preference

B.R. September 01, 2014 10:58AM

Re: SSL ciphers preference

Maxim Dounin September 01, 2014 02:08PM

Re: SSL ciphers preference

B.R. September 01, 2014 02:38PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 230
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready