Hi Jeff,
Don't know if you ran across this, but maybe it will be some assistance,
https://www.digicert.com/kb/ssl-support/ssl-enabling-perfect-forward-secrecy.htm
Hope you are doing well.
Brian
On 2/2/21 6:33 PM, Jeffrey Ross via users wrote:
System is Fedora 33 I'm attempting to enable Perfect Forwarding
Secrecy (PFS) in Apache.
I started by setting the options I wanted in Apache only to find that
the SSL options for Ciphers are ignored in the Apache configuration
and instead are pulled from /etc/crypto-policies/back-ends directory.
I was able to disallow any TLS protocol below 1.2 in
opensslcnf.config, but not sure what I need to enable PFS.
Suggestions would be appreciated.
Thanks Jeff
_______________________________________________
users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/users@xxxxxxxxxxxxxxxxxxxxxxx
_______________________________________________
users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/users@xxxxxxxxxxxxxxxxxxxxxxx