「SSL」:修訂間差異
跳至導覽
跳至搜尋
第4行: | 第4行: | ||
目前的設定,只支援有FS(Forward secrecy)的協定(不斷行): | 目前的設定,只支援有FS(Forward secrecy)的協定(不斷行): | ||
<pre>CHACHA20+ECDHE:AESGCM+ECDHE:AES+ECDHE:CAMELLIA+ECDHE:!ADH:!AECDH:!DSS:!ECDSA:!MD5:!SHA1</pre> | <pre>CHACHA20+ECDHE:AESGCM+ECDHE:AES+ECDHE:CAMELLIA+ECDHE:!ADH:!AECDH:!DSS:!ECDSA:!MD5:!SHA1</pre> | ||
如果要考慮到舊的瀏覽器,拿掉 SHA1 限制: | |||
<pre>CHACHA20+ECDHE:AESGCM+ECDHE:AES+ECDHE:CAMELLIA+ECDHE:!ADH:!AECDH:!DSS:!ECDSA:!MD5</pre> | |||
== 外部連結 == | == 外部連結 == | ||
* [https://mozilla.github.io/server-side-tls/ssl-config-generator/ Generate Mozilla Security Recommended Web Server Configuration Files] | * [https://mozilla.github.io/server-side-tls/ssl-config-generator/ Generate Mozilla Security Recommended Web Server Configuration Files] | ||
* [https://wiki.mozilla.org/Security/Server_Side_TLS Security/Server Side TLS - MozillaWiki] | * [https://wiki.mozilla.org/Security/Server_Side_TLS Security/Server Side TLS - MozillaWiki] |
於 2018年8月8日 (三) 08:26 的修訂
SSL(英語:Secure Sockets Layer),或TLS(英語:Transport Layer Security),是一個安全協定。
設定
目前的設定,只支援有FS(Forward secrecy)的協定(不斷行):
CHACHA20+ECDHE:AESGCM+ECDHE:AES+ECDHE:CAMELLIA+ECDHE:!ADH:!AECDH:!DSS:!ECDSA:!MD5:!SHA1
如果要考慮到舊的瀏覽器,拿掉 SHA1 限制:
CHACHA20+ECDHE:AESGCM+ECDHE:AES+ECDHE:CAMELLIA+ECDHE:!ADH:!AECDH:!DSS:!ECDSA:!MD5