|
|
@@ -198,35 +198,27 @@ connection_timeout=300
|
|
|
# If an "or above" version is used, the best will be negotiated. So if both
|
|
|
# ends are able to do TLSv1.2 and use specify SSLv2, you will get TLSv1.2.
|
|
|
|
|
|
-# ssl_version=SSLv2+
|
|
|
-ssl_version=TLSv1+
|
|
|
+#ssl_version=SSLv2+
|
|
|
|
|
|
# SSL USE ADH
|
|
|
# This is for backward compatibility and is DEPRECATED. Set to 1 to enable
|
|
|
# ADH or 2 to require ADH. 1 is currently the default but will be changed
|
|
|
# in a later version.
|
|
|
|
|
|
-# ssl_use_adh=1
|
|
|
-# ssl_use_adh=2
|
|
|
+#ssl_use_adh=1
|
|
|
|
|
|
# SSL CIPHER LIST
|
|
|
# This lists which ciphers can be used. For backward compatibility, this
|
|
|
# defaults to 'ssl_cipher_list=ALL:!MD5:@STRENGTH' in this version but
|
|
|
# will be changed to something like the example below in a later version of NRPE.
|
|
|
|
|
|
-# ssl_cipher_list=ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH
|
|
|
-ssl_cipher_list=ALL:!MD5:@STRENGTH
|
|
|
-# ssl_cipher_list=ADH
|
|
|
-# ssl_cipher_list=ECDH
|
|
|
+#ssl_cipher_list=ALL:!MD5:@STRENGTH
|
|
|
|
|
|
# SSL Certificate and Private Key Files
|
|
|
|
|
|
#ssl_cacert_file=/etc/ssl/servercerts/ca-cert.pem
|
|
|
#ssl_cert_file=/etc/ssl/servercerts/nagios-cert.pem
|
|
|
#ssl_privatekey_file=/etc/ssl/servercerts/nagios-key.pem
|
|
|
-ssl_cacert_file=/usr/local/nagios/etc/ssl/ca/ca_cert.pem
|
|
|
-ssl_cert_file=/usr/local/nagios/etc/ssl/server_certs/db_server.pem
|
|
|
-ssl_privatekey_file=/usr/local/nagios/etc/ssl/server_certs/db_server.key
|
|
|
|
|
|
# SSL USE CLIENT CERTS
|
|
|
# This options determines client certificate usage.
|
|
|
@@ -234,7 +226,7 @@ ssl_privatekey_file=/usr/local/nagios/etc/ssl/server_certs/db_server.key
|
|
|
# 1 = Ask for client certificates
|
|
|
# 2 = Require client certificates
|
|
|
|
|
|
-ssl_client_certs=2
|
|
|
+#ssl_client_certs=0
|
|
|
|
|
|
# SSL LOGGING
|
|
|
# This option determines which SSL messages are send to syslog. OR values
|
|
|
@@ -249,7 +241,7 @@ ssl_client_certs=2
|
|
|
# 0x20 (32) = Log details of client's certificate if it has one
|
|
|
# -1 or 0xff or 0x2f = All of the above
|
|
|
|
|
|
-ssl_logging=0x2f
|
|
|
+#ssl_logging=0x00
|
|
|
|
|
|
|
|
|
|