Browse Source

exclude SSLv3 for all TLS

to mitigate POODLE vulnerability
Sven Neuhaus 10 years ago
parent
commit
ac59435d6e
1 changed files with 2 additions and 0 deletions
  1. 2
    0
      roles/mailserver/templates/etc_postfix_main.cf.j2

+ 2
- 0
roles/mailserver/templates/etc_postfix_main.cf.j2 View File

38
 # TLS parameters
38
 # TLS parameters
39
 smtpd_tls_mandatory_protocols=!SSLv2,!SSLv3
39
 smtpd_tls_mandatory_protocols=!SSLv2,!SSLv3
40
 smtp_tls_mandatory_protocols=!SSLv2,!SSLv3
40
 smtp_tls_mandatory_protocols=!SSLv2,!SSLv3
41
+smtp_tls_protocols = !SSLv2,!SSLv3
42
+smtpd_tls_protocols = !SSLv2,!SSLv3
41
 smtpd_tls_cert_file=/etc/ssl/certs/wildcard_combined.pem
43
 smtpd_tls_cert_file=/etc/ssl/certs/wildcard_combined.pem
42
 smtpd_tls_key_file=/etc/ssl/private/wildcard_private.key
44
 smtpd_tls_key_file=/etc/ssl/private/wildcard_private.key
43
 smtpd_use_tls=yes
45
 smtpd_use_tls=yes

Loading…
Cancel
Save