Security/Server Side TLS: Difference between revisions

Jump to navigation Jump to search
No edit summary
Line 76: Line 76:
* DH Parameter size: '''1024'''
* DH Parameter size: '''1024'''
* Elliptic curves: '''secp256r1, secp384r1, secp521r1'''
* Elliptic curves: '''secp256r1, secp384r1, secp521r1'''
* Certificate signature '''must''' use '''SHA-1''' (windows XP is incompatible with sha-256)
* Certificate signature: '''SHA-1''' (windows XP pre-sp3 is incompatible with sha-256)


If your version of OpenSSL is old, unavailable ciphers will be discarded automatically. Always use the full ciphersuite above and let OpenSSL pick the ones it supports.
If your version of OpenSSL is old, unavailable ciphers will be discarded automatically. Always use the full ciphersuite above and let OpenSSL pick the ones it supports.
Confirmed users
529

edits

Navigation menu