
226
FLASH
MEDIA
SERVER
4.5
CONFIGURATION
AND
ADMINISTRATION
XML configuration files reference
Last updated 11/28/2012
The components can be combined with the appropriate prefixes to create a list of ciphers, including only those ciphers
the server is prepared to accept, in the order of preference.
Example
This cipher string instructs the server to accept all ciphers except those using anonymous or ephemeral Diffie-Hellman
key exchange.
<SSLCipherSuite>ALL:!ADH:!EDH</SSLCipherSuite>
These cipher strings instruct the server to accept only RSA key exchange and refuse export or null encryption. The
server evaluates both strings as equivalent.
<SSLCipherSuite>RSA:!NULL!EXP</SSLCipherSuite>
<SSLCipherSuite>RSA:LOW:MEDIUM:HIGH</SSLCipherSuite>
This cipher list instructs the server to accept all ciphers but place them in order of decreasing strength. This sequencing
allows clients to negotiate for the strongest cipher that both they and the server can accept.
<SSLCipherSuite>ALL:+HIGH:+LOW:+EXP:+NULL</SSLCipherSuite>
This string instructs the server to accept only high- and medium-strength encryption, with the high being preferred,
and reject export-strength versions.
<SSLCipherSuite>ALL:+HIGH:!LOW:!EXP:!NULL</SSLCipherSuite>
This string instructs the server to accept all ciphers but to order them so that SSLv2 ciphers come after SSLv3 ciphers.
<SSLCipherSuite>ALL:+SSLv2</SSLCipherSuite>
The following is the complete list of components that the server can evaluate.
Key exchange algorithm
Description
kRSA
Key exchange
kDHr
Diffie-Hellman key exchange with RSA key
kDHd
Diffie-Hellman key exchange with DSA key
RSA
Ephemeral Diffie-Hellman key exchange
DH
RSA key exchange
EDH
Ephemeral Diffie-Hellman key exchange
ADH
Anonymous Diffie-Hellman key exchange
Authentication methods
Description
aNULL
No authentication
aRSA
RSA authentication
aDSS
DSS authentication
aDH
Diffie-Hellman authentication