On 08.05.2016 18:31, Pierre Schmitz wrote:
> I'd like to enable h2 on luna. Are there any objections?

If it doesn't cause any problems, no objection.

> ssl_prefer_server_ciphers on;
> ssl_protocols TLSv1 TLSv1.1 TLSv1.2;

I hope those are already set.


This enables different ciphers than those published by bettercrypto.org
which I believe we use. Especially it enables some DHE-DSS ciphers which
I don't know anything about. I'm assuming it's a different name for DSA,
but I wonder why those are not included in the bettercrypto suite.
Additionally your suite would enable ECDHE-ECDSA ciphers which are also
excluded by bettercrypto. Could you check why they specifically exclude
them and if their reasoning matters for us?

The bettercrypto.org list is `openssl ciphers
| tr ":" "\n"` while yours is `openssl ciphers

I also just eyeballed the lists. You may want to diff them just in case
I missed something.


