]> Frank Brehm's Git Trees - pixelpark/hiera.git/commitdiff
changed ssl cipher suites on dev/test-web(01/02)-pfizer-de revert
authorsascha.strassheim <sascha.strassheim@pixelpark.com>
Wed, 14 Feb 2018 12:18:13 +0000 (13:18 +0100)
committersascha.strassheim <sascha.strassheim@pixelpark.com>
Wed, 14 Feb 2018 12:18:13 +0000 (13:18 +0100)
customer/pfizer/dev-web01-pfizer-de.pixelpark.net.yaml
customer/pfizer/dev-web02-pfizer-de.pixelpark.net.yaml
customer/pfizer/test-web01-pfizer-de.pixelpark.net.yaml

index 479cd9b21e13bd8bbcd23e1e62ed195607eb4e0a..a591b932998468900a4ee0be09d9b77843e3d129 100644 (file)
@@ -82,8 +82,8 @@ infra::profile::drupal::projects:
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
-    ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
-    ssl_protocols: 'TLSv1.2'
+#    ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
+#    ssl_protocols: 'TLSv1.2'
     #ssl_cipher              ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP
     #SetEnvIf User-Agent         ".*MSIE.*" nokeepalive ssl-unclean-shutdown downgrade-1.0 force-response-1.0
     directories:
@@ -143,7 +143,7 @@ infra::profile::typo3::projects:
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
     ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
-    ssl_protocols: 'TLSv1.2'     
+    ssl_protocols: 'TLSv1.2'
     directories:
       - provider: locationmatch
         path: '^/(?!(server-status|server-info))'
index c4e1a7b8fabcef5bd49fa183e1b06781b7cd9e20..548a4680b11b4e9a6ea01a7f19ddda8f55d9f6ac 100644 (file)
@@ -68,8 +68,8 @@ infra::profile::typo3::projects:
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
-    ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
-    ssl_protocols: 'TLSv1.2' 
+#    ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
+#    ssl_protocols: 'TLSv1.2' 
 
     #ssl_cipher:    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP
     #SetEnvIf User-Agent   ".*MSIE.*" nokeepalive ssl-unclean-shutdown downgrade-1.0 force-response-1.0
index fe233609da31b27afeeafb997afff094466e2068..da3022c8a9e54d523c621cb1b78f7848f33e259b 100644 (file)
@@ -58,8 +58,8 @@ infra::profile::drupal::projects:
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
-    ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
-    ssl_protocols: 'TLSv1.2'
+#    ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
+#    ssl_protocols: 'TLSv1.2'
     directories:
       - directory_root:
         provider: directory
@@ -128,7 +128,7 @@ infra::profile::typo3::projects:
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
     ssl_ciphers: 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'
-    ssl_protocols: 'TLSv1.2'     
+    ssl_protocols: 'TLSv1.2'
     headers:
       - 'set X-Frame-Options: ALLOW-FROM=http://pfizerprodedev8.prod.acquia-sites.com/'
       - 'set X-XSS-Protection: "1; mode=block"'