diff options
| author | Dmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com> | 2015-06-15 11:50:21 +0000 |
|---|---|---|
| committer | Dmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com> | 2015-06-15 11:50:21 +0000 |
| commit | 9522a710e5d02d8cd30c69ad386974072f533233 (patch) | |
| tree | 9aaf93d165aa4218e9e095f49a89a2128935afc8 /doc/release | |
| parent | 7300729190f4e61c4e71f18d0a81ea044eaad98a (diff) | |
| parent | 86d35ed3d4dd564ec7f5f8551fe5e65f5c4e5cd2 (diff) | |
| download | gitlab-ce-9522a710e5d02d8cd30c69ad386974072f533233.tar.gz | |
Merge branch 'update_ssl_ciphers' into 'master'
Update ssl ciphers
Removing all DHE suites from Nginx template SSL ciphers.
This will deny forward secrecy for Android 2.3.7, Java 6 and OpenSSL 0.9.8. but will give A+ rating on SSL labs.
Google sites also do not have DHE suites, [source](https://community.qualys.com/blogs/securitylabs/2013/06/25/ssl-labs-deploying-forward-secrecy)
> Google's sites, for example, tend to not have any DHE suites in their configuration. [2013]
See merge request !814
Diffstat (limited to 'doc/release')
0 files changed, 0 insertions, 0 deletions
