| 203 |
- |
1 |
# Policy DEFAULT dump
|
|
|
2 |
#
|
|
|
3 |
# Do not parse the contents of this file with automated tools,
|
|
|
4 |
# it is provided for review convenience only.
|
|
|
5 |
#
|
|
|
6 |
# Baseline values for all scopes:
|
| 192 |
- |
7 |
cipher = AES-256-GCM AES-256-CCM CHACHA20-POLY1305 CAMELLIA-256-GCM AES-256-CTR AES-256-CBC CAMELLIA-256-CBC AES-128-GCM AES-128-CCM CAMELLIA-128-GCM AES-128-CTR AES-128-CBC CAMELLIA-128-CBC
|
|
|
8 |
group = X25519 X448 SECP256R1 SECP384R1 SECP521R1 FFDHE-2048 FFDHE-3072 FFDHE-4096 FFDHE-6144 FFDHE-8192
|
|
|
9 |
hash = SHA2-256 SHA2-384 SHA2-512 SHA3-256 SHA3-384 SHA3-512 SHA2-224 SHA1
|
|
|
10 |
key_exchange = ECDHE RSA DHE DHE-RSA PSK DHE-PSK ECDHE-PSK ECDHE-GSS DHE-GSS
|
|
|
11 |
mac = AEAD HMAC-SHA2-256 HMAC-SHA1 UMAC-128 HMAC-SHA2-384 HMAC-SHA2-512
|
| 203 |
- |
12 |
protocol =
|
|
|
13 |
sign = ECDSA-SHA3-256 ECDSA-SHA2-256 ECDSA-SHA3-384 ECDSA-SHA2-384 ECDSA-SHA3-512 ECDSA-SHA2-512 EDDSA-ED25519 EDDSA-ED448 RSA-PSS-SHA2-256 RSA-PSS-SHA2-384 RSA-PSS-SHA2-512 RSA-SHA3-256 RSA-SHA2-256 RSA-SHA3-384 RSA-SHA2-384 RSA-SHA3-512 RSA-SHA2-512 ECDSA-SHA2-224 RSA-PSS-SHA2-224 RSA-SHA2-224 ECDSA-SHA1 RSA-PSS-SHA1 RSA-SHA1
|
|
|
14 |
arbitrary_dh_groups = 1
|
| 192 |
- |
15 |
min_dh_size = 2048
|
|
|
16 |
min_dsa_size = 2048
|
|
|
17 |
min_rsa_size = 2048
|
|
|
18 |
sha1_in_certs = 1
|
|
|
19 |
ssh_certs = 1
|
|
|
20 |
ssh_etm = 1
|
| 203 |
- |
21 |
# Scope-specific properties derived for select backends:
|
|
|
22 |
cipher@gnutls = AES-256-GCM AES-256-CCM CHACHA20-POLY1305 AES-256-CBC AES-128-GCM AES-128-CCM AES-128-CBC
|
|
|
23 |
protocol@gnutls = TLS1.3 TLS1.2 DTLS1.2
|
|
|
24 |
cipher@java-tls = AES-256-GCM AES-256-CCM CHACHA20-POLY1305 AES-256-CBC AES-128-GCM AES-128-CCM AES-128-CBC
|
|
|
25 |
protocol@java-tls = TLS1.3 TLS1.2 DTLS1.2
|
|
|
26 |
protocol@libreswan = IKEv2
|
|
|
27 |
cipher@nss = AES-256-GCM AES-256-CCM CHACHA20-POLY1305 AES-256-CBC AES-128-GCM AES-128-CCM AES-128-CBC
|
|
|
28 |
protocol@nss = TLS1.3 TLS1.2 DTLS1.2
|
|
|
29 |
cipher@openssl = AES-256-GCM AES-256-CCM CHACHA20-POLY1305 AES-256-CBC AES-128-GCM AES-128-CCM AES-128-CBC
|
|
|
30 |
protocol@openssl = TLS1.3 TLS1.2 DTLS1.2
|