summaryrefslogtreecommitdiff
path: root/factory-default
diff options
context:
space:
mode:
authorBertrand Jacquin <bertrand@jacquin.bzh>2018-08-19 00:09:52 +0100
committerBertrand Jacquin <bertrand@jacquin.bzh>2018-08-19 00:11:40 +0100
commit45111395a668edb3526725a0702565c5782a79de (patch)
tree4c3a4d059cb69ce5e69d159fca22c27fe4a019e9 /factory-default
parentfactory-default: Bump app-admin/syslog-ng to 3.16.1 (diff)
downloadportage-45111395a668edb3526725a0702565c5782a79de.tar.xz
factory-default: Enforce TLSv1.2 and ECDHE-RSA-AES256-GCM-SHA384
Diffstat (limited to 'factory-default')
-rw-r--r--factory-default/app-admin/syslog-ng-3.17.1/etc/syslog-ng/conf.d/0001-send-via-syslog.conf4
-rw-r--r--factory-default/app-admin/syslog-ng/etc/syslog-ng/conf.d/0001-send-via-syslog.conf4
2 files changed, 6 insertions, 2 deletions
diff --git a/factory-default/app-admin/syslog-ng-3.17.1/etc/syslog-ng/conf.d/0001-send-via-syslog.conf b/factory-default/app-admin/syslog-ng-3.17.1/etc/syslog-ng/conf.d/0001-send-via-syslog.conf
index 003145d6..69ee5484 100644
--- a/factory-default/app-admin/syslog-ng-3.17.1/etc/syslog-ng/conf.d/0001-send-via-syslog.conf
+++ b/factory-default/app-admin/syslog-ng-3.17.1/etc/syslog-ng/conf.d/0001-send-via-syslog.conf
@@ -3,7 +3,9 @@ destination d_log.pants-on.net {
transport(tls)
tls(ca_dir("/etc/ssl/certs")
peer_verify(required-trusted)
- cipher-suite(AES256-GCM-SHA384)
+ ssl-options(no-sslv2, no-sslv3, no-tlsv1, no-tlsv11)
+ ecdh-curve-list("prime256v1:secp384r1")
+ cipher-suite("ECDHE-RSA-AES256-GCM-SHA384")
)
);
};
diff --git a/factory-default/app-admin/syslog-ng/etc/syslog-ng/conf.d/0001-send-via-syslog.conf b/factory-default/app-admin/syslog-ng/etc/syslog-ng/conf.d/0001-send-via-syslog.conf
index 003145d6..69ee5484 100644
--- a/factory-default/app-admin/syslog-ng/etc/syslog-ng/conf.d/0001-send-via-syslog.conf
+++ b/factory-default/app-admin/syslog-ng/etc/syslog-ng/conf.d/0001-send-via-syslog.conf
@@ -3,7 +3,9 @@ destination d_log.pants-on.net {
transport(tls)
tls(ca_dir("/etc/ssl/certs")
peer_verify(required-trusted)
- cipher-suite(AES256-GCM-SHA384)
+ ssl-options(no-sslv2, no-sslv3, no-tlsv1, no-tlsv11)
+ ecdh-curve-list("prime256v1:secp384r1")
+ cipher-suite("ECDHE-RSA-AES256-GCM-SHA384")
)
);
};