4 ms·
For specific advice, here's my blog post with a proposed configuration that will work with any program that relies on OpenSSL: http://blog.ivanristic.com/2
by ivanr 13y ago
For specific advice, here's my blog post with a proposed configuration that will work with any program that relies on OpenSSL:
http://blog.ivanristic.com/2013/08/configuring-apache-nginx-and-openssl-for-forward-secrecy.html
But I've found in practice that many operate under different circumstances. For example, many hardware devices offer only a limited set of cipher suites. To know how to configure them, you have to understand the advantages and limitations of each.
That's why I keep the SSL/TLS Deployment Best Practices higher level, without specific cipher suite configuration examples:
https://www.ssllabs.com/projects/best-practices/
- bradleyjg 13y agoIn the blog post above you say that IE 8 on XP doesn't support PFS, but this technet document seems to indicate that a few cipher suites with DHE are available on XP: http://msdn.microsoft.com/en-us/library/windows/desktop/aa380512(v=vs.85).aspx http://msdn.microsoft.com/en-us/library/windows/desktop/aa38... Are all of them problematic for other reasons? Thanks for all your work in this area!
- ivanr 13y agoYes, they are problematic. Cipher suites are typically tied to a particular key algorithm. Microsoft does support the DHE key exchange, but only in combination with DSA keys (DSS in the cipher suite string). There are a couple of problems with that. First, if you do use DSA keys, you don't get to use any RSA suites[1], which are much better supported. Just as an illustration Chrome supports only one DSA suite. Second, virtually no one uses DSA keys today for SSL. So, all the advice you will find is about RSA keys. Third, and worst, Microsoft does not actually support DSA keys stronger than 1024 bits, and you can't use 1024-bit keys because they're considered too weak. I am sure there is a reason, but Microsoft never supported the DHE and RSA combination, which was the only way to achieve Forward Secrecy before ECDHE became widely supported. [1] Actually, some web servers support multiple keys/certificates. With Apache, for example, you could have an SSL site with RSA, DSA, and ECDSA keys if you wanted. I think nginx is adding this capability too. But IIS does not support it.