easy-admin
easy-admin copied to clipboard
Scripts for easy system administration
Encrypt then MAC should not be used with ChaChaPoly1305 Source: https://terrapin-attack.com/
During server algorithm key exchange (KEX) neogitation, The NIST P256 part of ECDSA should be avoided. Instead, recommends ecdh-sha2-nistp521 ecdh-sha2-nistp384 This author leans toward avoidance of P384 as penalty cost...
During the encryption part of server algorithm negotiation, CBC is to be avoided: use GCM or CTR. The main difference between GCM and CTR is that GCM also provides authentication...
No details giving.
Drop down to lower bits within SHA2 remains problematic.