浏览代码

[Dovecot] Minor changes to ciphers, still disallow insecure ciphers

André 7 年之前
父节点
当前提交
5905a3919c
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      data/conf/dovecot/dovecot.conf

+ 1 - 1
data/conf/dovecot/dovecot.conf

@@ -22,7 +22,7 @@ mail_plugins = quota acl zlib listescape #mail_crypt
 ssl_min_protocol = TLSv1
 
 ssl_prefer_server_ciphers = yes
-ssl_cipher_list = EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA256:EECDH:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!IDEA:!ECDSA:kEDH:CAMELLIA128-SHA:AES128-SHA
+ssl_cipher_list = ALL:!ADH:!LOW:!SSLv2:!SSLv3:!EXP:!aNULL:!eNULL:!3DES:!MD5:!PSK:!DSS:!RC4:!SEED:!IDEA:+HIGH:+MEDIUM
 
 # Default in Dovecot 2.3
 ssl_options = no_compression