summaryrefslogtreecommitdiffstats
path: root/etc/inc/system.inc
diff options
context:
space:
mode:
authordhatz <dhatz-fw@hyper.net>2013-07-01 04:16:33 +0300
committerjim-p <jimp@pfsense.org>2013-07-14 16:15:49 -0400
commitab17ed4e70cc8cd8337846525a3694d81fffff32 (patch)
tree71190545776c2cb3fbb409e45501cad8f54716ca /etc/inc/system.inc
parentda60727cead91cc475c6fa2ddb2309ab79962467 (diff)
downloadpfsense-ab17ed4e70cc8cd8337846525a3694d81fffff32.zip
pfsense-ab17ed4e70cc8cd8337846525a3694d81fffff32.tar.gz
support mitigating BEAST attack
According to http://redmine.lighttpd.net/projects/lighttpd/wiki/Release-1_4_30 "...by setting ssl.cipher-list = "ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4-SHA:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM" you can mitigate BEAST attacks."
Diffstat (limited to 'etc/inc/system.inc')
-rw-r--r--etc/inc/system.inc3
1 files changed, 2 insertions, 1 deletions
diff --git a/etc/inc/system.inc b/etc/inc/system.inc
index 0a5fba5..876dba6 100644
--- a/etc/inc/system.inc
+++ b/etc/inc/system.inc
@@ -1184,7 +1184,8 @@ EOD;
// Harden SSL a bit for PCI conformance testing
$lighty_config .= "ssl.use-sslv2 = \"disable\"\n";
- $lighty_config .= "ssl.cipher-list = \"DHE-RSA-CAMELLIA256-SHA:DHE-DSS-CAMELLIA256-SHA:CAMELLIA256-SHA:DHE-DSS-AES256-SHA:AES256-SHA:DHE-RSA-CAMELLIA128-SHA:DHE-DSS-CAMELLIA128-SHA:CAMELLIA128-SHA:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA:AES128-SHA:RC4-SHA:RC4-MD5:!aNULL:!eNULL:!3DES:@STRENGTH\"\n";
+ $lighty_config .= "ssl.honor-cipher-order = \"enable\"\n";
+ $lighty_config .= "ssl.cipher-list = \"ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4-SHA:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM\"\n";
if(!(empty($ca) || (strlen(trim($ca)) == 0)))
$lighty_config .= "ssl.ca-file = \"{$g['varetc_path']}/{$ca_location}\"\n\n";
OpenPOWER on IntegriCloud