From: Aaron Kaplan Date: Fri, 17 Oct 2014 10:14:43 +0000 (+0200) Subject: no SSLv3 damn it X-Git-Url: https://git.bettercrypto.org/ach-master.git/commitdiff_plain/4f7d76eb7d395b66cf12eab0c57b135c9f9277a0 no SSLv3 damn it --- diff --git a/src/configuration/MailServers/cyrus-imapd/imapd.conf b/src/configuration/MailServers/cyrus-imapd/imapd.conf index f60586d..20a2c1b 100644 --- a/src/configuration/MailServers/cyrus-imapd/imapd.conf +++ b/src/configuration/MailServers/cyrus-imapd/imapd.conf @@ -260,7 +260,7 @@ tls_session_timeout: 1440 # selects TLSv1 high-security ciphers only, and removes all anonymous ciphers # from the list (because they provide no defense against man-in-the-middle # attacks). It also orders the list so that stronger ciphers come first. -tls_cipher_list: EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA +tls_cipher_list: EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:!SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA # Require a client certificate for ALL services (imap, pop3, lmtp, sieve). #tls_require_cert: false