On Mon, 2018-12-10 at 04:22 -0800, Alice Wonder wrote: > ssl_min_protocol = TLSv1.2 > ssl_cipher_list = > EECDH+CHACHA20:EECDH+AESGCM:EECDH+SHA384:EECDH+SHA256:EECDH:!3DES:!RC4 > :!ADH:!LOW@STRENGTH > ssl_prefer_server_ciphers = yes
Don't forget about ssl_dh_parameters_length, it's default on Debian is 1024. -Jim P.