3 ms·
My side project tries to give secure default settings for all major webservers and other software (like haproxy, mysql, mailservers etc): https://cipherli.st/ h
by mdewinter 11y ago
My side project tries to give secure default settings for all major webservers and other software (like haproxy, mysql, mailservers etc): https://cipherli.st/ https://cipherli.st/
From the start it has listed the suggestion to set up >2048 DH keys.
If you want to test your site for export ciphers, you can try my other side project: https://tls.so/ https://tls.so/ - you can also use the SSL labs test but mine is faster for just testing ciphersuite. (And it's open source, so you can use it internally as well).
Mozilla also has a good wiki page for SSL settings: https://wiki.mozilla.org/Security/Server_Side_TLS https://wiki.mozilla.org/Security/Server_Side_TLS
- ZoFreX 11y agoThanks to your guide, I didn't have to change a single thing when this news broke. Excellent work!
- r1ch 11y agoAny chance of adding STARTTLS support to tls.so? I've found a lack of decent tools to scan FTP servers, SMTP servers, etc.
- aidenn0 11y agoThanks a bunch, it's fairly easy to find configs for HTTP servers (and SSL labs won't check non 443 ports), but I also run a dovecot server, and this made it easy to check; I had no clue SSLv3 was enabled by default, for example. Sadly my current phone is stuck on SSLv3 so until I replace it I have no mail on my phone anymore.
- eckes 11y agoAlso check out Applebaums Duraconf: https://github.com/ioerror/duraconf https://github.com/ioerror/duraconf