{"id":723,"date":"2015-05-21T14:08:27","date_gmt":"2015-05-21T12:08:27","guid":{"rendered":"http:\/\/ndk.sytes.net\/wordpress\/?p=723"},"modified":"2017-08-03T18:23:01","modified_gmt":"2017-08-03T16:23:01","slug":"secure-crypto-ciphers-centos","status":"publish","type":"post","link":"https:\/\/ndk.sytes.net\/wordpress\/?p=723","title":{"rendered":"Secure crypto ciphers CentOS"},"content":{"rendered":"<p>\n\tHere are two lists of secure (at date of writing) ciphers for the CentOS\/RHEL operating system. These lists are not complete but only reduced to RSA\/AES encryption ciphers which are considered secure. Use following command to get all supported ciphers on your OS:\n<\/p>\n<pre>\r\nopenssl ciphers -v ALL<\/pre>\n<p>\n\tFollowing string uses secure ciphers while keeping some of the older secure ciphers available. This string can be used in apache, postfix or others:\n<\/p>\n<pre>\r\nECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5<\/pre>\n<p>\n\t<strong>CentOS 6+7:<\/strong>\n<\/p>\n<p>\n\tECDHE-RSA-AES256-GCM-SHA384<br \/>\n\tECDHE-RSA-AES256-SHA384<br \/>\n\tECDHE-RSA-AES256-SHA<br \/>\n\tDHE-RSA-AES256-GCM-SHA384<br \/>\n\tDHE-RSA-AES256-SHA256<br \/>\n\tDHE-RSA-AES256-SHA<br \/>\n\tECDH-RSA-AES256-GCM-SHA384<br \/>\n\tECDH-RSA-AES256-SHA384<br \/>\n\tECDH-RSA-AES256-SHA<br \/>\n\tECDHE-RSA-AES128-GCM-SHA256<br \/>\n\tECDHE-RSA-AES128-SHA256<br \/>\n\tECDHE-RSA-AES128-SHA<br \/>\n\tDHE-RSA-AES128-GCM-SHA256<br \/>\n\tDHE-RSA-AES128-SHA256<br \/>\n\tDHE-RSA-AES128-SHA<br \/>\n\tECDH-RSA-AES128-GCM-SHA256<br \/>\n\tECDH-RSA-AES128-SHA256<br \/>\n\tECDH-RSA-AES128-SHA\n<\/p>\n<p style=\"margin-bottom: 0in; line-height: 100%\">\n\t&nbsp;\n<\/p>\n<p style=\"margin-bottom: 0in; line-height: 100%\">\n\t<strong>CentOS 5:<\/strong>\n<\/p>\n<p class=\"p1\">\n\t<span class=\"s1\">DHE-RSA-AES256-SHA<br \/>\n\tDHE-RSA-AES128-SHA<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here are two lists of secure (at date of writing) ciphers for the CentOS\/RHEL operating system. These lists are not complete but only reduced to RSA\/AES encryption ciphers which are considered secure. Use following command to get all supported ciphers on your OS: openssl ciphers -v ALL Following string uses secure ciphers while keeping some [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-723","post","type-post","status-publish","format-standard","hentry","category-servers"],"_links":{"self":[{"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/723","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=723"}],"version-history":[{"count":1,"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/723\/revisions"}],"predecessor-version":[{"id":951,"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/723\/revisions\/951"}],"wp:attachment":[{"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ndk.sytes.net\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}