-
@bortzmeyer Remove DH completly. Currently no more supported browser side. And very very slower and weaker than ECDH.
-
@bortzmeyer And disable non-PFS cipher suite too :P
-
@bortzmeyer @hgshoggins And currently You also priorize AES256 then AES128, so you prefer non-pfs AES256 to pfs AES128 /o\
aeris22’s Twitter Archive—№ 46,960