{"id":4322,"date":"2014-10-28T09:22:03","date_gmt":"2014-10-28T08:22:03","guid":{"rendered":"https:\/\/www.bdjl.de\/localhost\/?p=4322"},"modified":"2014-12-10T08:08:25","modified_gmt":"2014-12-10T07:08:25","slug":"zu-sicher","status":"publish","type":"post","link":"https:\/\/www.bdjl.de\/localhost\/?p=4322","title":{"rendered":"Zu sicher"},"content":{"rendered":"<p>Beachte: <a title=\"SSL, Apache, Komfort und Sicherheit III\" href=\"https:\/\/www.bdjl.de\/localhost\/?p=4393\">Update des Beitrags!<\/a><\/p>\n<p>Nach den <a title=\"SSL Check\" href=\"https:\/\/www.bdjl.de\/localhost\/?p=4317\">Anpassungen der Apache Configuration<\/a> in Folge des Poodle Bugs erhielt ich zu Beginn der Woche eine R\u00fcckmeldung einer Vista Nutzerin aus dem Kollegium, dass sie nicht mehr auf unsere Seiten zugreifen k\u00f6nne. Ich nahm das zuerst nicht weiter ernst, tippte auf lokale Probleme. Dann stellte ich unter <a href=\"http:\/\/cubian.org\/\" target=\"_blank\">Cubian X <\/a>fest, dass Chromium nur noch einen 113er Fehler anzeigte, der f\u00fcr<\/p>\n<blockquote><p>ERR_SSL_VERSION_OR_CIPHER_MISMATCH<\/p><\/blockquote>\n<p>steht und Iceweasel merkte an<\/p>\n<blockquote><p>ssl_error_no_cypher_overlap<\/p><\/blockquote>\n<p>Diverse Browser unter Android 4.0.3 (Lightning, Tint Browser, Zirco) wollten ebenfalls nicht mehr meine eigenen HTTPS verschl\u00fcsselten Seiten aufrufen. W\u00e4hrend unter Android der Firefox noch einsetzbar war, so ging auf meinem Spielkistchen mit Cubian X gar nichts mehr. Die Software auf diesem System l\u00e4sst sich nicht einfach aktualisieren &#8211; meine Apache-Konfiguration war f\u00fcr das Ding schlicht &#8222;zu sicher&#8220;.<\/p>\n<p>Ich kam dann irgendwann auf Idee, die unterst\u00fctzten Cipher Suiten miteinander zu vergleichen. Das geht direkt bei <a href=\"https:\/\/www.ssllabs.com\/\" target=\"_blank\">Qualys SSL Labs<\/a> &#8211; oder f\u00fcr den Browser auch hier:\u00a0<a href=\"https:\/\/cc.dcsec.uni-hannover.de\/check\" target=\"_blank\">https:\/\/cc.dcsec.uni-hannover.de\/check<\/a> . Die Schuppen fielen dann endlich von den Augen.<\/p>\n<h2>Sichere Konfiguration<\/h2>\n<p>Eintrag:<\/p>\n<blockquote><p>SSLProtocol all -SSLv2 -SSLv3<\/p>\n<p>SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!SSLv3:!EXPORT<\/p><\/blockquote>\n<p>Ergebnis unter Debian:<\/p>\n<p><a href=\"https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/kvfgnet_debianssl.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-4325\" src=\"https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/kvfgnet_debianssl-640x403.png\" alt=\"kvfgnet_debianssl\" width=\"640\" height=\"403\" srcset=\"https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/kvfgnet_debianssl-640x403.png 640w, https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/kvfgnet_debianssl-624x392.png 624w, https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/kvfgnet_debianssl.png 821w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>Unterst\u00fctzte Browsersuiten:<\/p>\n<table class=\"reportTable\">\n<thead>\n<tr>\n<td class=\"tableHead\" colspan=\"4\">Handshake Simulation<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=2.3.7\">Android 2.3.7<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.0.4\">Android 4.0.4<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.1.1\">Android 4.1.1<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.2.2\">Android 4.2.2<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.3\">Android 4.3<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.4.2\">Android 4.4.2<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=BingBot&amp;version=Dec%202013\">BingBot Dec 2013<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=BingPreview&amp;version=Jun%202014\">BingPreview Jun 2014<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Chrome&amp;version=37&amp;platform=OS%20X\">Chrome 37 \/ OS X<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (<code>0xc02f<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Firefox&amp;version=24.2.0%20ESR&amp;platform=Win%207\">Firefox 24.2.0 ESR \/ Win 7<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Firefox&amp;version=32&amp;platform=OS%20X\">Firefox 32 \/ OS X<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (<code>0xc02f<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Googlebot&amp;version=Jun%202014\">Googlebot Jun 2014<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=6&amp;platform=XP\">IE 6 \/ XP<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser effectively does not support Forward Secrecy.\">No FS <sup>1<\/sup><\/span> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=7&amp;platform=Vista\">IE 7 \/ Vista<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=8&amp;platform=XP\">IE 8 \/ XP<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser effectively does not support Forward Secrecy.\">No FS <sup>1<\/sup><\/span> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=8%2d10&amp;platform=Win%207\">IE 8-10 \/ Win 7<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=11&amp;platform=Win%207\">IE 11 \/ Win 7<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA256 (<code>0x3c<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=11&amp;platform=Win%208.1\">IE 11 \/ Win 8.1<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE%20Mobile&amp;version=10&amp;platform=Win%20Phone%208.0\">IE Mobile 10 \/ Win Phone 8.0<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE%20Mobile&amp;version=11&amp;platform=Win%20Phone%208.1\">IE Mobile 11 \/ Win Phone 8.1<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA256 (<code>0x3c<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Java&amp;version=6u45\">Java 6u45<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Java&amp;version=7u25\">Java 7u25<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Java&amp;version=8b132\">Java 8b132<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (<code>0xc027<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=OpenSSL&amp;version=0.9.8y\">OpenSSL 0.9.8y<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=OpenSSL&amp;version=1.0.1h\">OpenSSL 1.0.1h<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=5.1.9&amp;platform=OS%20X%2010.6.8\">Safari 5.1.9 \/ OS X 10.6.8<\/a><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=6&amp;platform=iOS%206.0.1\">Safari 6 \/ iOS 6.0.1<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=7&amp;platform=iOS%207.1\">Safari 7 \/ iOS 7.1<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=8&amp;platform=iOS%208.0%20Beta\">Safari 8 \/ iOS 8.0 Beta<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=6.0.4&amp;platform=OS%20X%2010.8.4\">Safari 6.0.4 \/ OS X 10.8.4<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=7&amp;platform=OS%20X%2010.9\">Safari 7 \/ OS X 10.9<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Yahoo%20Slurp&amp;version=Jun%202014\">Yahoo Slurp Jun 2014<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=YandexBot&amp;version=Sep%202014\">YandexBot Sep 2014<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(3) Only first connection attempt simulated. Browsers tend to retry with a lower protocol version.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(R) Denotes a reference browser or client, with which we expect better effective security.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 &amp; 7, older IE).<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u00dcberarbeitete Konfiguration<\/h2>\n<p>Eintrag:<\/p>\n<blockquote><p>SSLProtocol all -SSLv2 -SSLv3<\/p>\n<p>SSLCipherSuite HIGH:MEDIUM:!aNULL:!MD5<\/p><\/blockquote>\n<p>Ergebnis unter Debian:<\/p>\n<p><a href=\"https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/debianssl.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-4323\" src=\"https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/debianssl-640x437.png\" alt=\"debianssl\" width=\"640\" height=\"437\" srcset=\"https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/debianssl-640x437.png 640w, https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/debianssl-624x426.png 624w, https:\/\/www.bdjl.de\/localhost\/wp-content\/uploads\/2014\/10\/debianssl.png 822w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>Unterst\u00fctzte Browsersuiten:<\/p>\n<table class=\"reportTable\">\n<thead>\n<tr>\n<td class=\"tableHead\" colspan=\"4\">Handshake Simulation<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=2.3.7\">Android 2.3.7<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_RC4_128_SHA (<code>0x5<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> \u00a0<span style=\"color: #f88017;\"> RC4<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.0.4\">Android 4.0.4<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (<code>0xc014<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.1.1\">Android 4.1.1<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (<code>0xc014<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.2.2\">Android 4.2.2<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (<code>0xc014<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.3\">Android 4.3<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (<code>0xc014<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Android&amp;version=4.4.2\">Android 4.4.2<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=BingBot&amp;version=Dec%202013\">BingBot Dec 2013<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA (<code>0x2f<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=BingPreview&amp;version=Jun%202014\">BingPreview Jun 2014<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_DHE_RSA_WITH_AES_256_CBC_SHA (<code>0x39<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Chrome&amp;version=37&amp;platform=OS%20X\">Chrome 37 \/ OS X<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (<code>0xc02f<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Firefox&amp;version=24.2.0%20ESR&amp;platform=Win%207\">Firefox 24.2.0 ESR \/ Win 7<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (<code>0xc014<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Firefox&amp;version=32&amp;platform=OS%20X\">Firefox 32 \/ OS X<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (<code>0xc02f<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Googlebot&amp;version=Jun%202014\">Googlebot Jun 2014<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_RC4_128_SHA (<code>0xc011<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> \u00a0<span style=\"color: #f88017;\"> RC4<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=6&amp;platform=XP\">IE 6 \/ XP<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser effectively does not support Forward Secrecy.\">No FS <sup>1<\/sup><\/span> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" colspan=\"2\"><span style=\"color: red;\">Protocol or cipher suite mismatch<\/span><\/td>\n<td class=\"tableRight\"><span style=\"color: red;\">Fail<sup>3<\/sup><\/span><\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=7&amp;platform=Vista\">IE 7 \/ Vista<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA (<code>0x2f<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=8&amp;platform=XP\">IE 8 \/ XP<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser effectively does not support Forward Secrecy.\">No FS <sup>1<\/sup><\/span> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_RC4_128_SHA (<code>0x5<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: grey;\">No FS<\/span> \u00a0<span style=\"color: #f88017;\"> RC4<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=8%2d10&amp;platform=Win%207\">IE 8-10 \/ Win 7<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA (<code>0x2f<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=11&amp;platform=Win%207\">IE 11 \/ Win 7<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA256 (<code>0x3c<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE&amp;version=11&amp;platform=Win%208.1\">IE 11 \/ Win 8.1<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE%20Mobile&amp;version=10&amp;platform=Win%20Phone%208.0\">IE Mobile 10 \/ Win Phone 8.0<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA (<code>0x2f<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=IE%20Mobile&amp;version=11&amp;platform=Win%20Phone%208.1\">IE Mobile 11 \/ Win Phone 8.1<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_AES_128_CBC_SHA256 (<code>0x3c<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Java&amp;version=6u45\">Java 6u45<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_RSA_WITH_RC4_128_SHA (<code>0x5<\/code>) \u00a0<span class=\"dhParams\"> <span style=\"color: #f88017;\">No FS<\/span> \u00a0<span style=\"color: #f88017;\"> RC4<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Java&amp;version=7u25\">Java 7u25<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (<code>0xc013<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Java&amp;version=8b132\">Java 8b132<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (<code>0xc027<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=OpenSSL&amp;version=0.9.8y\">OpenSSL 0.9.8y<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_DHE_RSA_WITH_AES_256_CBC_SHA (<code>0x39<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=OpenSSL&amp;version=1.0.1h\">OpenSSL 1.0.1h<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=5.1.9&amp;platform=OS%20X%2010.6.8\">Safari 5.1.9 \/ OS X 10.6.8<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (<code>0xc013<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">128<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=6&amp;platform=iOS%206.0.1\">Safari 6 \/ iOS 6.0.1<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=7&amp;platform=iOS%207.1\">Safari 7 \/ iOS 7.1<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=8&amp;platform=iOS%208.0%20Beta\">Safari 8 \/ iOS 8.0 Beta<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=6.0.4&amp;platform=OS%20X%2010.8.4\">Safari 6.0.4 \/ OS X 10.8.4<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\">TLS 1.0<\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (<code>0xc014<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Safari&amp;version=7&amp;platform=OS%20X%2010.9\">Safari 7 \/ OS X 10.9<\/a> \u00a0<span class=\"dhParams\"><span style=\"color: green;\">R<\/span><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (<code>0xc028<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=Yahoo%20Slurp&amp;version=Jun%202014\">Yahoo Slurp Jun 2014<\/a> \u00a0 <span class=\"dhParams\" title=\"Browser does not support Server Name Indication.\">No SNI <sup>2<\/sup><\/span><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td class=\"tableLeft\" width=\"180\"><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewClient.html?name=YandexBot&amp;version=Sep%202014\">YandexBot Sep 2014<\/a><\/td>\n<td class=\"tableLeft\" width=\"60\"><span style=\"color: green;\">TLS 1.2<\/span><\/td>\n<td class=\"tableLeft\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (<code>0xc030<\/code>) \u00a0<span class=\"dhParams\"> <span class=\"highlight\">FS<\/span> <\/span><\/td>\n<td class=\"tableRight\">256<\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(3) Only first connection attempt simulated. Browsers tend to retry with a lower protocol version.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(R) Denotes a reference browser or client, with which we expect better effective security.<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"4\"><span style=\"color: grey;\">(All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 &amp; 7, older IE).<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Beachte: Update des Beitrags! Nach den Anpassungen der Apache Configuration in Folge des Poodle Bugs erhielt ich zu Beginn der Woche eine R\u00fcckmeldung einer Vista Nutzerin aus dem Kollegium, dass sie nicht mehr auf unsere Seiten zugreifen k\u00f6nne. Ich nahm das zuerst nicht weiter ernst, tippte auf lokale Probleme. Dann stellte ich unter Cubian X [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,10,294],"tags":[340,440,314,179,474,453,140],"class_list":["post-4322","post","type-post","status-publish","format-standard","hentry","category-linux","category-schule","category-tablet-cubietruck","tag-apache","tag-cubian","tag-debian","tag-firefox","tag-iceweasel","tag-ssl","tag-verschlusselung"],"_links":{"self":[{"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=\/wp\/v2\/posts\/4322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4322"}],"version-history":[{"count":6,"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=\/wp\/v2\/posts\/4322\/revisions"}],"predecessor-version":[{"id":4400,"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=\/wp\/v2\/posts\/4322\/revisions\/4400"}],"wp:attachment":[{"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bdjl.de\/localhost\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}