To avoid a situation where future security improvements are held back by crufty configuration that was added in a well-intended effort to improve present-day security, I think we should be encouraging blacklists instead; the OpenSSL cipher list spec actually supports blacklisting.
[1]: https://github.com/cloudflare/sslconfig/blob/master/conf
Of course, you sound like exactly the kind of sysadmin I'm not concerned about ;-)
Now I give my recommendations as an ordered list of suites. It's easy to set up, does exactly what you want and, as a bonus, everyone can look at the list and understand which suites exactly are configured.
That said, I'd like to see good default configurations in libraries and server programs, which can be updated via patches as needed. Then we wouldn't really need to bother with cipher suite configuration at all.
0 - https://www.imperialviolet.org/2014/02/27/tlssymmetriccrypto...