Bug#928173: apache2: SSLCipherSuite is ignored
On Monday, 29 April 2019 13:22:56 CEST Olaf Zaplinski wrote:
> I have set
> SSLCipherSuite "-ALL ECDHE-ECDSA-CHACHA20-POLY1305
> ECDHE-RSA-CHACHA20-POLY1305 ECDHE-ECDSA-AES256-GCM-SHA384" in
> SSLProtocol is not defined anywhere. SSLCipherSuite is only defined here.
> According to Qualsys SSL labs test, non-defined ciphers are being used, e.g.
> Expectation: only defined three ciphers are being used.
apache2 in stretch still uses openssl 1.0 libs, while the command line utility
is already 1.1. This makes it difficult to check with "openssl ciphers" what is
openssl 1.0 does not support the chacha ciphers. But I don't know why apache
does not complain about the unknown ciphers. Probably that's a bug.
In buster / Debian 10, this seems to work better, because there apache2 links
against openssl 1.1.
But even there, things are weird. It does not seem possible to select a single
$ openssl ciphers ECDHE-RSA-AES256-GCM-SHA384