Project

General

Profile

Actions

Bug #12578

closed

Smart-Proxy doesn't enforce ciphersuite ordering

Added by Brandon Weeks about 9 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
SSL
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

The SSL settings don't enforce ciphersuite ordering, which may allow the clients to make worse decisions about ciphersuite selection or maliciously downgraded. Enabling the 'SSLHonorCipherOrder' or 'ssl_prefer_server_ciphers' settings for Apache or Nginx is considered a best practice.

Actions

Also available in: Atom PDF