Browse Source

feat(dbmaster): enforce strong TLS ciphers

Peter Thomassen 8 years ago
parent
commit
324ffb14d4
1 changed files with 4 additions and 3 deletions
  1. 4 3
      dbmaster/51-server.cnf

+ 4 - 3
dbmaster/51-server.cnf

@@ -1,7 +1,8 @@
 [mysqld]
 [mysqld]
-ssl-ca   = /etc/ssl/private/db/ca.pem
-ssl-cert = /etc/ssl/private/db/dev.desec.io-cert.pem
-ssl-key  = /etc/ssl/private/db/dev.desec.io-key.pem
+ssl-ca     = /etc/ssl/private/db/ca.pem
+ssl-cert   = /etc/ssl/private/db/dev.desec.io-cert.pem
+ssl-key    = /etc/ssl/private/db/dev.desec.io-key.pem
+ssl-cipher = EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
 
 
 server-id               = 1
 server-id               = 1
 log_bin                 = /var/log/mysql/mysql-bin.log
 log_bin                 = /var/log/mysql/mysql-bin.log