blob: a4eedbf01939e9328c92d9fa81d46bcd3ffae5f0 [file] [log] [blame]
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +03001parameters:
2 _param:
3 apache_ssl_enabled: false
4 apache_ssl:
5 mode: 'strict'
6 enabled: ${_param:apache_ssl_enabled}
7 engine: salt
8 prefer_server_ciphers: "on"
9 protocols:
10 all:
11 name: 'all'
12 enabled: True
13 excludeSSLv2:
14 name: '-SSLv2'
15 enabled: True
16 excludeSSLv3:
17 name: '-SSLv3'
18 enabled: True
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000019 excludeTLSv1:
20 name: '-TLSv1'
21 enabled: True
22 excludeTLSv1.1:
23 name: '-TLSv1.1'
24 enabled: True
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030025 ciphers:
26 ECDHE-ECDSA-CHACHA20-POLY1305:
27 name: 'ECDHE-ECDSA-CHACHA20-POLY1305'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000028 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030029 ECDHE-RSA-CHACHA20-POLY1305:
30 name: 'ECDHE-RSA-CHACHA20-POLY1305'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000031 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030032 ECDHE-ECDSA-AES128-GCM-SHA256:
33 name: 'ECDHE-ECDSA-AES128-GCM-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000034 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030035 ECDHE-RSA-AES128-GCM-SHA256:
36 name: 'ECDHE-RSA-AES128-GCM-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000037 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030038 ECDHE-ECDSA-AES256-GCM-SHA384:
39 name: 'ECDHE-ECDSA-AES256-GCM-SHA384'
40 enabled: True
41 ECDHE-RSA-AES256-GCM-SHA384:
42 name: 'ECDHE-RSA-AES256-GCM-SHA384'
43 enabled: True
44 DHE-RSA-AES128-GCM-SHA256:
45 name: 'DHE-RSA-AES128-GCM-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000046 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030047 DHE-RSA-AES256-GCM-SHA384:
48 name: 'DHE-RSA-AES256-GCM-SHA384'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000049 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030050 ECDHE-ECDSA-AES128-SHA256:
51 name: 'ECDHE-ECDSA-AES128-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000052 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030053 ECDHE-RSA-AES128-SHA256:
54 name: 'ECDHE-RSA-AES128-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000055 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030056 ECDHE-ECDSA-AES128-SHA:
57 name: 'ECDHE-ECDSA-AES128-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000058 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030059 ECDHE-RSA-AES256-SHA384:
60 name: 'ECDHE-RSA-AES256-SHA384'
61 enabled: True
62 ECDHE-RSA-AES128-SHA:
63 name: 'ECDHE-RSA-AES128-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000064 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030065 ECDHE-ECDSA-AES256-SHA384:
66 name: 'ECDHE-ECDSA-AES256-SHA384'
67 enabled: True
68 ECDHE-ECDSA-AES256-SHA:
69 name: 'ECDHE-ECDSA-AES256-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000070 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030071 ECDHE-RSA-AES256-SHA:
72 name: 'ECDHE-RSA-AES256-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000073 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030074 DHE-RSA-AES128-SHA256:
75 name: 'DHE-RSA-AES128-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000076 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030077 DHE-RSA-AES128-SHA:
78 name: 'DHE-RSA-AES128-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000079 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030080 DHE-RSA-AES256-SHA256:
81 name: 'DHE-RSA-AES256-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000082 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030083 DHE-RSA-AES256-SHA:
84 name: 'DHE-RSA-AES256-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000085 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030086 ECDHE-ECDSA-DES-CBC3-SHA:
87 name: 'ECDHE-ECDSA-DES-CBC3-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000088 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030089 ECDHE-RSA-DES-CBC3-SHA:
90 name: 'ECDHE-RSA-DES-CBC3-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000091 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030092 EDH-RSA-DES-CBC3-SHA:
93 name: 'EDH-RSA-DES-CBC3-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000094 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030095 AES128-GCM-SHA256:
96 name: 'AES128-GCM-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +000097 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030098 AES256-GCM-SHA384:
99 name: 'AES256-GCM-SHA384'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +0000100 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300101 AES128-SHA256:
102 name: 'AES128-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +0000103 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300104 AES256-SHA256:
105 name: 'AES256-SHA256'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +0000106 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300107 AES256-SHA:
108 name: 'AES256-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +0000109 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300110 AES128-SHA:
111 name: 'AES128-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +0000112 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300113 DES-CBC3-SHA:
114 name: 'DES-CBC3-SHA'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +0000115 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300116 removeDSS:
117 name: '!DSS'
Oleksandr Shyshko2b2c3042019-02-08 13:35:24 +0000118 enabled: True