6 ms·
"So, the way to go with BEAST is to force RC4 with TLS 1.0 and earlier, some CBC suite with TLS 1.1, and GCM suites with TLS 1.2." Is it possible to configure
by hiroprot 13y ago
"So, the way to go with BEAST is to force RC4 with TLS 1.0 and earlier, some CBC suite with TLS 1.1, and GCM suites with TLS 1.2."
Is it possible to configure nginx like this? From what I can tell, there is no way to select a cipher based on the protocol.
- ivanr 13y agoYes, it's possible. OpenSSL does not allow for per-protocol tuning, but there are some tricks you can use to achieve the same effect. In particular, GCM suites and SHA256/SHA384 suites work only in TLS 1.2, so if you put those first you are effectively prioritizing them on per protocol-basis. Try this: AESGCM:SHA384:SHA256:RC4:AES !aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!kEDH:!PSK:!SRP:!kECDH This is from an example that's not related to PFS, so some tuning may be needed. The example is from my (free) OpenSSL Cookbook, which you can get from here: https://www.feistyduck.com/books/bulletproof-ssl-tls-and-pki/ https://www.feistyduck.com/books/bulletproof-ssl-tls-and-pki... You are required to register in order to get the book (because the book is not just the PDF). If you don't want to receive any email from me, after you log in, go to the Settings section and unsubscribe from the marketing list.
- hiroprot 13y agoThanks, this is helpful. Which CBC suites work in TLS 1.1, but not 1.0? These are my test results: https://www.ssllabs.com/ssltest/analyze.html?d=forkly.com https://www.ssllabs.com/ssltest/analyze.html?d=forkly.com
- ivanr 13y agoIn general, I don't think the protocol specifications call for some suites to be allowed with certain protocol and some not to. (There are some exceptions, when weak suites need to be deprecated.) In practice, it comes down to how library developers have implemented them. For example, in OpenSSL, you have SSL v2 suites, TLS 1.2 suites, and >= SSL v3 suites. I don't think there are any TLS 1.1-only suites.
- hiroprot 13y agoOkay, then my current config is probably as good as it gets for now. Thanks for the help :)