Hi Jeff,

Don't know if you ran across this, but maybe it will be some assistance,

https://www.digicert.com/kb/ssl-support/ssl-enabling-perfect-forward-secrecy.htm

Hope you are doing well.

Brian

On 2/2/21 6:33 PM, Jeffrey Ross via users wrote:
System is Fedora 33 I'm attempting to enable Perfect Forwarding Secrecy (PFS) in Apache.

I started by setting the options I wanted in Apache only to find that the SSL options for Ciphers are ignored in the Apache configuration and instead are pulled from /etc/crypto-policies/back-ends directory.

I was able to disallow any TLS protocol below 1.2 in opensslcnf.config, but not sure what I need to enable PFS.

Suggestions would be appreciated.

Thanks Jeff
_______________________________________________
users mailing list -- users@lists.fedoraproject.org
To unsubscribe send an email to users-le...@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/users@lists.fedoraproject.org
_______________________________________________
users mailing list -- users@lists.fedoraproject.org
To unsubscribe send an email to users-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/users@lists.fedoraproject.org

Reply via email to