<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[沧海一粟]]></title> 
<link>http://www.dzhope.com/index.php</link> 
<description><![CDATA[Web系统架构与服务器运维,php开发]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[沧海一粟]]></copyright>
<item>
<link>http://www.dzhope.com/post//</link>
<title><![CDATA[配置 Nginx SSL禁用弱加密算法]]></title> 
<author>jed &lt;jed521@163.com&gt;</author>
<category><![CDATA[服务器技术]]></category>
<pubDate>Thu, 20 Jan 2022 07:21:55 +0000</pubDate> 
<guid>http://www.dzhope.com/post//</guid> 
<description>
<![CDATA[ 
	通过命令： nmap -sV --script ssl-enum-ciphers -p 443 <a href="http://www.example.com" target="_blank">www.example.com</a> 可得：<br/><div class="code"><br/>Starting Nmap 6.40 ( http://nmap.org ) at 2021-10-08 14:51 CST<br/>Nmap scan report for 127.0.0.1<br/>Host is up (0.035s latency).<br/>PORT&nbsp;&nbsp;&nbsp;&nbsp;STATE SERVICE VERSION<br/>443/tcp open&nbsp;&nbsp;http&nbsp;&nbsp;&nbsp;&nbsp;nginx 1.19.10<br/>&#124; ssl-enum-ciphers: <br/>&#124;&nbsp;&nbsp; TLSv1.2: <br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp; ciphers: <br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDHE_RSA_WITH_RC4_128_SHA - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA - broken<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDH_anon_WITH_AES_128_CBC_SHA - broken<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDH_anon_WITH_AES_256_CBC_SHA - broken<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_ECDH_anon_WITH_RC4_128_SHA - broken<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 - weak<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_EXPORT_WITH_RC4_40_MD5 - weak<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_WITH_AES_128_CBC_SHA - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_WITH_AES_256_CBC_SHA - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_WITH_AES_256_CBC_SHA256 - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_WITH_AES_256_GCM_SHA384 - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TLS_RSA_WITH_CAMELLIA_128_CBC_SHA - strong<br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp; compressors: <br/>&#124;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NULL<br/>&#124;_&nbsp;&nbsp;least strength: strong<br/><br/>Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .<br/>Nmap done: 1 IP address (1 host up) scanned in 8.09 seconds<br/></div><br/><br/>结果中weak(柔弱的)、broken(损坏的)、strong(坚固的)字段表示加密强度，为了安全需要将128位以下弱加密算法禁用，Nginx 配置 SSL需明确指定算法：<br/><div class="code"><br/>ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!3DES:!ADH:!RC4:!DH:!DHE;<br/></div><br/><br/>重启是nginx.conf配置生效<br/><div class="code"><br/>nginx -s reload<br/></div>
]]>
</description>
</item><item>
<link>http://www.dzhope.com/post//#blogcomment</link>
<title><![CDATA[[评论] 配置 Nginx SSL禁用弱加密算法]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.dzhope.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>