From 04bd46f2b238c052fe98a538c3601da131ccc343 Mon Sep 17 00:00:00 2001 From: Guilhem Moulin Date: Tue, 27 Oct 2015 16:13:40 +0100 Subject: stunnel: use GCM ciphers only; use SSL options rather than ciphers to disable protocols. --- roles/munin-master/templates/etc/stunnel/munin-master.conf.j2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'roles/munin-master/templates/etc/stunnel') diff --git a/roles/munin-master/templates/etc/stunnel/munin-master.conf.j2 b/roles/munin-master/templates/etc/stunnel/munin-master.conf.j2 index c025183..51c5dca 100644 --- a/roles/munin-master/templates/etc/stunnel/munin-master.conf.j2 +++ b/roles/munin-master/templates/etc/stunnel/munin-master.conf.j2 @@ -40,7 +40,7 @@ options = SINGLE_ECDH_USE options = SINGLE_DH_USE ; Select permitted SSL ciphers -ciphers = EECDH+AES:EDH+AES:!MEDIUM:!LOW:!EXP:!aNULL:!eNULL:!SSLv2:!SSLv3:!TLSv1:!TLSv1.1 +ciphers = EECDH+AESGCM:!MEDIUM:!LOW:!EXP:!aNULL:!eNULL ; ************************************************************************** ; * Service definitions (remove all services for inetd mode) * -- cgit v1.2.3