Cov txheej txheem:

Kuv yuav ua li cas lov tes taw outdated versions ntawm SSL TLS hauv Apache?
Kuv yuav ua li cas lov tes taw outdated versions ntawm SSL TLS hauv Apache?

Video: Kuv yuav ua li cas lov tes taw outdated versions ntawm SSL TLS hauv Apache?

Video: Kuv yuav ua li cas lov tes taw outdated versions ntawm SSL TLS hauv Apache?
Video: Ntsaim vaj - Muaj poj niam lawm ua tsis tau li cas ( Official MV ) Nkauj tawm tshiab 2020 2024, Kaum ib hlis
Anonim

Yuav ua li cas lov tes taw outdated versions ntawm SSL / TLS hauv Apache

  1. Siv vi (los yog vim) los kho ssl .
  2. Nrhiav tus SSL Kev them nyiaj yug raws tu qauv seem:
  3. Saib cov kab SSLProtocol tag nrho -SSLv2 -SSLv3, los ntawm kev ntxiv cov cim hash nyob rau hauv pem hauv ntej ntawm nws.
  4. Ntxiv ib kab hauv qab nws:
  5. Peb muaj disabled TLS 1.0 / 1.1 thiab SSL 2.0 / 3.0, thiab tab tom tshawb nrhiav ntxiv SSL Cipher Suite.

Raws li txoj cai, kuv yuav ua li cas thiaj li tsis siv TLS kev ruaj ntseg?

Left-click lub iav icon:

  1. Xaiv "Internet xaiv" los ntawm cov ntawv qhia zaub mov dropdown:
  2. Nyem qhov "Advanced" tab, scroll down thiab deselect "SSL 3.0" thiab "TLS 1.0".
  3. Nyem "OK" kom lees txais koj cov kev hloov pauv, uas yuav tsum tau siv tam sim ntawd.
  4. Hauv "Nrhiav" teb, sau "tls".

Ib tug kuj yuav nug, Kuv yuav ua li cas thiaj li tsis siv SSLv3 hauv Apache? Apache: Disabling SSL v3 raws tu qauv

  1. Nrhiav koj tus SSL Protocol Configuration ntawm koj Apache server. Piv txwv li,
  2. Ntxiv lossis hloov kho cov kab hauv qab no hauv koj qhov kev teeb tsa: SSLProtocol tag nrho -SSLv2 -SSLv3.
  3. Rov pib Apache. Piv txwv li, ntaus cov lus txib hauv qab no:
  4. Koj tau ua tiav qhov kev siv SSL v3 raws tu qauv.

Hais txog qhov no, kuv yuav ua li cas lov tes taw tsis muaj zog SSL raws tu qauv thiab ciphers hauv Apache?

Disable tsis muaj zog ciphers hauv Apache + CentOS

  1. Kho cov ntaub ntawv hauv qab no. vi /etc/httpd/conf.d/ssl.conf.
  2. Nias qhov tseem ceeb "hloov thiab G" mus rau qhov kawg ntawm cov ntaub ntawv.
  3. Luam thiab muab cov kab hauv qab no.
  4. Peb yuav tsum xyuas kom meej cov kab peb ntxiv rau cov ntaub ntawv config tsis muaj kev pab los ntawm lub neej ntawd.
  5. Txuag cov ntaub ntawv hauv "vi" los ntawm kev khiav ":wq"
  6. Rov pib Apache.

Kuv yuav lov tes taw TLS hauv Linux li cas?

Txhawm rau lov tes taw TLS 1.0:

  1. Khiav cov lus txib hauv qab no kom tshem tawm TLS 1.0 los ntawm SSL raws tu qauv: sudo sed -i 's/TLSv1 //' /etc/nginx/conf.d/ssfe.conf.
  2. Paub meej tias cov kev hloov pauv hauv SSL raws tu qauv siv cov lus txib hauv qab no:
  3. Rov pib qhov kev pabcuam ngix rau cov kev hloov pauv kom muaj txiaj ntsig:
  4. Ntsuam xyuas qhov kev teeb tsa tshiab siv SSL Server Test lub vev xaib.

Pom zoo: