Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

cPanel disable Cipher Suites

Discussion in 'Security' started by ca2236, Jun 22, 2018.

  1. ca2236

    ca2236 Well-Known Member

    Joined:
    Feb 2, 2018
    Messages:
    50
    Likes Received:
    7
    Trophy Points:
    8
    Location:
    Nebraska
    cPanel Access Level:
    DataCenter Provider
    Hello,

    I found various posts and pages around the net on disabling cipher suites, however, I had a question on how to do it in cpanel.

    I think I do it here:
    • Home » Service Configuration » Apache Configuration » Global Configuration
    and then the SSL Cipher Suite

    but I don't know how to call the protocol names.

    I want to disable TLS_RSA_WITH_AES_128_GCM_SHA256 (for example)

    I think I do with with a exclamation point. but now sure of the name. There are other weak TLSA_RSA_AES with various names and 'features'. Is there a way to blank disable all of them? If not, how do I figure out each of the names?

    Edit: I found this site:
    mod_ssl - Apache HTTP Server Version 2.5

    Which I think helps, but, I still am working through figuring out the correct cipher-tag for each (I think that is the right name)

    Thanks
     
    #1 ca2236, Jun 22, 2018
    Last edited: Jun 22, 2018
  2. cPanelLauren

    cPanelLauren Forums Analyst
    Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    1,814
    Likes Received:
    133
    Trophy Points:
    118
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    Hi @ca2236

    You should be able to disable with a ! as indicated on the mod_ssl documentation where they show the null ciphers disabled:
    Ultimately you might want to check out secure cipher examples and use something of that nature rather than go through them piece by piece. The documentation here might be helpful:
    SSL/TLS Strong Encryption: How-To - Apache HTTP Server Version 2.4
    Generate Mozilla Security Recommended Web Server Configuration Files
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice