Re: [exim] some OpenSSL topics

Top Page
Delete this message
Reply to this message
Author: Wolfgang Breyha
Date:  
To: exim-users
Subject: Re: [exim] some OpenSSL topics
Viktor Dukhovni wrote, on 15.10.2013 02:42:
> On Mon, Oct 14, 2013 at 05:52:19PM +0200, Wolfgang Breyha wrote:
>> tls_require_ciphers = ECDH:kEDH:HIGH:RC4-SHA:!PSK:!KRB5:!aNULL:!MD5:!DES
>
> This cipher preference is broken. Exim SHOULD NOT encourage users
> to attempt to manually tweak OpenSSL cipherlists, even modestly
> clueful users get this badly wrong.


Exim never encouraged users to do so. Can you be a little bit more specific
why this cipher list is "broken"? At least the output of "openssl ciphers"
doesn't look that "broken".

Greetings, Wolfgang
--
Wolfgang Breyha <wbreyha@???> | http://www.blafasel.at/
Vienna University Computer Center | Austria