SSLHonorCipherOrder on Apache
Open Discussion
Please add support for SSLHonorCipherOrder on Apache config (WHM -> Apache Configuration -> Global Configuration )
http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslhonorcipherorder
Thanks for your interest in improving cPanel and WHM. This request does have an internal case, but has not yet been scheduled for inclusion in the product.
In the meantime, you can make these additions in the Pre Main include through WHM »Service Configuration »Apache Configuration »Include Editor.
Thanks for your interest in improving cPanel and WHM. This request does have an internal case, but has not yet been scheduled for inclusion in the product.
In the meantime, you can make these additions in the Pre Main include through WHM »Service Configuration »Apache Configuration »Include Editor.
Thanks for your interest in improving cPanel and WHM. This request does have an internal case, but has not yet been scheduled for inclusion in the product.
In the meantime, you can make these additions in the Pre Main include through WHM »Service Configuration »Apache Configuration »Include Editor.
Thanks for your interest in improving cPanel and WHM. This request does have an internal case, but has not yet been scheduled for inclusion in the product.
In the meantime, you can make these additions in the Pre Main include through WHM »Service Configuration »Apache Configuration »Include Editor.
Surely this one isn't exactly a biggie to add?
It's an important security feature, as some older devices will negotiate SSL ciphers that don't support forward secrecy unless you force them to by using the servers cipher order. Yes it's easy to add yourself, but it should be there by default.
cPanel should be striving to be as secure as possible out of the box and it requiring effort to weaken it, not the other way around, starting weak and requiring effort to make it passably secure.
Surely this one isn't exactly a biggie to add?
It's an important security feature, as some older devices will negotiate SSL ciphers that don't support forward secrecy unless you force them to by using the servers cipher order. Yes it's easy to add yourself, but it should be there by default.
cPanel should be striving to be as secure as possible out of the box and it requiring effort to weaken it, not the other way around, starting weak and requiring effort to make it passably secure.
Replies have been locked on this page!