And so begins years of copy/paste of cipher lists without knowing what they mean or do.
Your cipher list should be far more paired down than their list.
And unless you need IE6 support for SSL, you can disable SSLv3 (v2 should always be disabled)
Your cipher list should be far more paired down than their list.
And unless you need IE6 support for SSL, you can disable SSLv3 (v2 should always be disabled)
At the end of the day, it's not realistic to imagine that everyone will spend days researching this to come up with a proper ciphersuite. There is a strong need for guidance.
You are correct about SSLv3: it is up to each organization to stop supporting it. But do know that it is still widely used, if not in browser, in client libraries. I wouldn't turn it off on a corporation site if I were you.
[1] https://www.feistyduck.com/books/bulletproof-ssl-tls-and-pki...