mirror of https://github.com/zulip/zulip.git
62f1a9da26
• Specify disabled rather than enabled protocols, so as not to disable TLS 1.3. • Provide an explicit cipher suite list (Mozilla intermediate config version 5.4). • Respect the browser’s preferred cipher suite ordering over the server’s. • Use FFDHE2048 Diffie-Hellman parameters. • Disable SSL session tickets. (SSL stapling is also recommended but SSLStaplingCache cannot be configured inside a <VirtualHost> block.) Signed-off-by: Anders Kaseorg <anders@zulip.com> |
||
---|---|---|
.. | ||
authentication-methods.md | ||
deployment.md | ||
email-gateway.md | ||
email.md | ||
expensive-migrations.md | ||
export-and-import.md | ||
index.rst | ||
install-existing-server.md | ||
install.md | ||
maintain-secure-upgrade.md | ||
management-commands.md | ||
mobile-push-notifications.md | ||
multiple-organizations.md | ||
password-strength.md | ||
postgres.md | ||
requirements.md | ||
security-model.md | ||
settings.md | ||
ssl-certificates.md | ||
troubleshooting.md | ||
upgrade-or-modify.md | ||
upload-backends.md | ||
zoom-configuration.md |