#2626

OSGeo6 security remediation

Disable TLSV1 for http, https, smtp, postfix Disable SWEET32 cyper suite for https, http Disable use of JQuery 1.2 (this may be harder as I'm not sure what is using it. At anyrate needs to be upgrade to 3.5 or later

valid cert for mail, post-fix and disable weak hashing algorithms

to remedy:

1) was pointing at -- setup a fake site to show "Nothing here" as the default

And setup to get a letsencrpt cert for

2) Mail was using expired wildcard cert -- changed to use the letsencrypt one for by editing

/etc/postfix/ and also updated cypers

#smtpd_tls_exclude_ciphers = aNULL, eNULL, EXPORT, DES, RC4, MD5, PSK, aECDH, EDH-DSS-DES-CBC3-SHA, EDH-RSA-DES-CDC3-SHA, KRB5-DE5, CBC3-SHA
smtp_tls_exclude_ciphers = EXP, MEDIUM, LOW, DES, 3DES, SSLv2
smtpd_tls_exclude_ciphers = EXP, MEDIUM, LOW, DES, 3DES, SSLv2

systemctl restart postfix

