Re: Securing apache

2014-04-23 Thread Jochen Spieker
Sven Hartge: > Jochen Spieker wrote: > >> Makes sense. I hope they find a nice upgrade path for all involved >> packages. The transition to Apache 2.4 is probably going to be painful >> for years to come. > > Right now packages with DDs who care about easy backporting carry code > like this in t

Re: Securing apache

2014-04-23 Thread Sven Hartge
Jochen Spieker wrote: > Sven Hartge: >> Jochen Spieker wrote: >>> I didn't check, but I would be surprised if it was possible to only >>> install Apache 2.4 from testing without upgrading half of your >>> system. What you need is a backport -- Apache 2.4 compiled against >>> the library version

Re: Securing apache

2014-04-23 Thread Jochen Spieker
Sven Hartge: > Jochen Spieker wrote: > >> I didn't check, but I would be surprised if it was possible to only >> install Apache 2.4 from testing without upgrading half of your system. >> What you need is a backport -- Apache 2.4 compiled against the library >> versions available in wheezy. Curren

Re: Securing apache

2014-04-22 Thread Tanstaafl
On 4/22/2014 4:54 PM, Sven Hartge wrote: I doubt there will ever be a backport of apache2.4 to Wheezy. Ok, thanks guys... guess we can close this thread... -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.deb

Re: Securing apache

2014-04-22 Thread Sven Hartge
Jochen Spieker wrote: > Tanstaafl: >> I'm curious how many here enable the testing repo so they can run >> apache 2.4, which apparently is a bit more secure? If so, any gotchas >> or things to be aware of? > I didn't check, but I would be surprised if it was possible to only > install Apache 2.

Re: Securing apache

2014-04-22 Thread Jochen Spieker
Tanstaafl: > > I'm curious how many here enable the testing repo so they can run > apache 2.4, which apparently is a bit more secure? If so, any > gotchas or things to be aware of? I didn't check, but I would be surprised if it was possible to only install Apache 2.4 from testing without upgradin

Re: Securing apache

2014-04-22 Thread Tanstaafl
On 4/21/2014 1:25 PM, Jochen Spieker wrote: I use these settings and receive good results: SSLCipherSuite 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:

Re: Securing apache

2014-04-21 Thread Jochen Spieker
Tanstaafl: > On 4/21/2014 1:51 PM, Tanstaafl wrote: >> On 4/21/2014 1:25 PM, Jochen Spieker wrote: >>> SSLCipherSuite >>> 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DS

Re: Securing apache

2014-04-21 Thread Tanstaafl
On 4/21/2014 1:51 PM, Tanstaafl wrote: On 4/21/2014 1:25 PM, Jochen Spieker wrote: SSLCipherSuite 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:C

Re: Securing apache

2014-04-21 Thread Tanstaafl
On 4/21/2014 1:25 PM, Jochen Spieker wrote: SSLCipherSuite 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SH

Re: Securing apache

2014-04-21 Thread Tanstaafl
On 4/21/2014 1:25 PM, Jochen Spieker wrote: I use these settings and receive good results: SSLCipherSuite 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:

Re: Securing apache

2014-04-21 Thread Jochen Spieker
Tanstaafl: > Hi all, > > Noob-alert! > > Ok, a site I have inherited that is running debian (7.4) is running > Apache, and a test of the SSL for that site reveals a few issues I'd > like to address. > > First, the site checker I was using is: > > https://sslcheck.globalsign.com/en_US This appe

Securing apache

2014-04-21 Thread Tanstaafl
Hi all, Noob-alert! Ok, a site I have inherited that is running debian (7.4) is running Apache, and a test of the SSL for that site reveals a few issues I'd like to address. First, the site checker I was using is: https://sslcheck.globalsign.com/en_US The general results (and recommendatio