@@ -4,18 +4,20 @@ declaration template metaconfig/httpd/schema;
44include ' pan/types' ;
55include ' components/accounts/functions' ;
66
7- type httpd_sslprotocol = choice(" all" , " -SSLv3" , " -TLSv1" , " TLSv1" , " -TLSv1.1" , " TLSv1.1" , " TLSv1.2" , " TLSv1.3" );
7+ type httpd_sslprotocol = choice(" all" , " -SSLv3" , " -TLSv1" , " TLSv1" , " -TLSv1.1" , " TLSv1.1" , " TLSv1.2" , " TLSv1.3" ,
8+ " +TLSv1.2" , " +TLSv1.3" , " -all"
9+ );
810
911type httpd_ciphersuite = choice(" TLSv1" , " ECDHE-ECDSA-CHACHA20-POLY1305" , " ECDHE-RSA-CHACHA20-POLY1305" ,
10- " DHE-RSA-CHACHA20-POLY1305" , " ECDHE-ECDSA-AES128-GCM-SHA256" , " ECDHE-RSA-AES128-GCM-SHA256" ,
11- " ECDHE-ECDSA-AES256-GCM-SHA384" , " ECDHE-RSA-AES256-GCM-SHA384" , " DHE-RSA-AES128-GCM-SHA256" ,
12- " DHE-RSA-AES256-GCM-SHA384" , " ECDHE-ECDSA-AES128-SHA256" , " ECDHE-RSA-AES128-SHA256" ,
13- " ECDHE-ECDSA-AES128-SHA" , " ECDHE-RSA-AES256-SHA384" , " ECDHE-RSA-AES128-SHA" ,
14- " ECDHE-ECDSA-AES256-SHA384" , " ECDHE-ECDSA-AES256-SHA" , " ECDHE-RSA-AES256-SHA" ,
12+ " ECDHE-ECDSA-AES128-GCM-SHA256" , " ECDHE-RSA-AES128-GCM-SHA256" , " ECDHE-ECDSA-AES256-GCM-SHA384" ,
13+ " ECDHE-RSA-AES256-GCM-SHA384" , " DHE-RSA-AES128-GCM-SHA256" , " DHE-RSA-AES256-GCM-SHA384" ,
14+ " ECDHE-ECDSA-AES128-SHA256" , " ECDHE-RSA-AES128-SHA256" , " ECDHE-ECDSA-AES128-SHA" , " ECDHE-RSA-AES256-SHA384" ,
15+ " ECDHE-RSA-AES128-SHA" , " ECDHE-ECDSA-AES256-SHA384" , " ECDHE-ECDSA-AES256-SHA" , " ECDHE-RSA-AES256-SHA" ,
1516 " DHE-RSA-AES128-SHA256" , " DHE-RSA-AES128-SHA" , " DHE-RSA-AES256-SHA256" , " DHE-RSA-AES256-SHA" ,
1617 " ECDHE-ECDSA-DES-CBC3-SHA" , " ECDHE-RSA-DES-CBC3-SHA" , " EDH-RSA-DES-CBC3-SHA" , " AES128-GCM-SHA256" ,
17- " AES256-GCM-SHA384" , " AES128-SHA256" , " AES256-SHA256" , " AES128-SHA" , " AES256-SHA" , " DES-CBC3-SHA" , " !RC4" ,
18- " !LOW" , " !aNULL" , " !eNULL" , " !MD5" , " !EXP" , " !3DES" , " !IDEA" , " !SEED" , " !CAMELLIA" , " !DSS"
18+ " AES256-GCM-SHA384" , " AES128-SHA256" , " AES256-SHA256" , " AES128-SHA" , " AES256-SHA" , " DES-CBC3-SHA" ,
19+ " DHE-RSA-CHACHA20-POLY1305" , " !RC4" , " !LOW" , " !aNULL" , " !eNULL" , " !MD5" , " !EXP" , " !3DES" , " !IDEA" ,
20+ " !SEED" , " !CAMELLIA" , " !DSS"
1921);
2022
2123# These are the settings for old clients, see https://access.redhat.com/articles/1467293 for stricter values.
0 commit comments