~hloeung/charm-haproxy/bump-global-dh-param

« back to all changes in this revision

Viewing changes to config.yaml

  • Committer: Haw Loeung
  • Date: 2020-08-03 05:04:53 UTC
  • Revision ID: haw.loeung@canonical.com-20200803050453-qiae2nbd9407258h
Fixed description

Show diffs side-by-side

added added

removed removed

Lines of Context:
46
46
        Sets the maximum size of the Diffie-Hellman parameters used for generating
47
47
        the ephemeral/temporary Diffie-Hellman key in case of DHE key exchange.
48
48
        Default value if 2048, higher values will increase the CPU load, and values
49
 
        greater than 2048 bits are not supported by Java 7 and earlier clients. This
 
49
        greater than 1024 bits are not supported by Java 7 and earlier clients. This
50
50
        config key will be ignored if the installed haproxy package has no SSL support.
51
51
  global_default_bind_ciphers:
52
52
    default: ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:!DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:!DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:!CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA