RE: reverse https with squid

From: Chemolli Francesco (USI) <ChemolliF@dont-contact.us>
Date: Fri, 31 May 2002 16:06:42 +0200

> > https_port <youripaddresshere>:443
> > cert=/usr/local/squid_ssl/etc/certificate.pem
> > key=/usr/local/squid_ssl/etc/key.pem version=1
> >
> cipher=EDH-RSA-DES-CBC3-SHA:EDH-DSS-DES-CBC3-SHA:DES-CBC3-SHA:
> DES-CBC3-MD5:
> >D
> >
> HE-DSS-RC4-SHA:IDEA-CBC-SHA:RC4-SHA:RC4-MD5:IDEA-CBC-MD5:RC2-C
> BC-MD5:RC4-MD
> >5
> >
> >
> :RC4-64-MD5:EXP-EDH-RSA-DES-CBC-SHA:EXP-EDH-DSS-DES-CBC-SHA:EX
> P-DES-CBC-SHA
> > ::
> >
> > EXP-RC2-CBC-MD5:EXP-RC4-MD5:EXP-RC2-CBC-MD5:EXP-RC4-MD5
>
> There most likely can be simpler chiper expressions found for
> the same
> purpose.. such as DEFAULT:-EXPORT56

I have been reported that forcing use of the MD5 HASH could
be enough. MD5:@STRENGTH might be the "magic" key.

> There is also browsers having problems with TLS..

Very true.

-- 
	/kinkie 
Received on Fri May 31 2002 - 08:09:38 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:15:31 MST