Use the SSLProtocol blacklist approach

It turns out that specifying the ciphers we want to use leads to
breakage.  So instead we'll explicitly tell Apache which ciphers
we don't want to use.

Change-Id: I0f8211533495a6a4340c01dadb8069ccf9be429c
This commit is contained in:
Timothy Chavez 2014-10-16 11:37:17 -05:00
parent 0de9792bb6
commit 2a68660f4b

View File

@ -39,7 +39,7 @@
ServerName <%= scope.lookupvar("mediawiki::site_hostname") %> ServerName <%= scope.lookupvar("mediawiki::site_hostname") %>
SSLEngine on SSLEngine on
SSLProtocol +TLSv1 +TLSv1.1 +TLSv1.2 SSLProtocol All -SSLv2 -SSLv3
SSLCertificateFile <%= scope.lookupvar("mediawiki::ssl_cert_file") %> SSLCertificateFile <%= scope.lookupvar("mediawiki::ssl_cert_file") %>
SSLCertificateKeyFile <%= scope.lookupvar("mediawiki::ssl_key_file") %> SSLCertificateKeyFile <%= scope.lookupvar("mediawiki::ssl_key_file") %>
<% if scope.lookupvar("mediawiki::ssl_chain_file") != "" %> <% if scope.lookupvar("mediawiki::ssl_chain_file") != "" %>