# Configuring Older Cipher Suite Support for Servers - Mozilla TLS Config

**URL:** <https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204>\
**Category:** Help\
**Created:** [May 30, 2017, 7:54pm UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204 "2017-05-30T19:54:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gchiu](https://avatars.discourse-cdn.com/v4/letter/g/96bed5/32.png) [@gchiu](https://community.letsencrypt.org/u/gchiu)\
**Post date:** [May 30, 2017, 7:54pm UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204/1 "2017-05-30T19:54:11Z")

</div>

I’ve just in the last 2 days [installed https](https://forum.rebol.info) using letsencrypt following the recipe at [meta.discourse.org](https://meta.discourse.org/t/setting-up-lets-encrypt/40709) and it works fine for browsers, and I get an A+ rating on ssllabs.

But I have a client with support only for ancient ciphers.

So, how can I enable `TLS_DHE_RSA_WITH_AES_256_CBC_SHA` which is actually enabled for TLS 1.0 for this site `https://community.letsencrypt.org/` as per the SSLLABS [report](https://www.ssllabs.com/ssltest/analyze.html?d=community.letsencrypt.org&s=64.71.168.201)

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [May 30, 2017, 8:40pm UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204/2 "2017-05-30T20:40:04Z")

</div>

Hi @gchiu,

I would suggest using

[https://mozilla.github.io/server-side-tls/ssl-config-generator/](https://mozilla.github.io/server-side-tls/ssl-config-generator/)

You can then find the corresponding configuration lines in your web server configuration files and change them to those that the Mozilla generator suggested to you. In particular, if you choose “Old” instead of “Intermediate”, it will generate a configuration that will work with older clients. (The configuration that you have now is probably your web server’s default for HTTPS; unless I misread something in that recipe, I don’t believe that the recipe actually changed the defaults when enabling HTTPS.)

---

<div class="post-metadata">

**Author:** ![gchiu](https://avatars.discourse-cdn.com/v4/letter/g/96bed5/32.png) [@gchiu](https://community.letsencrypt.org/u/gchiu)\
**Post date:** [May 31, 2017, 2:07am UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204/3 "2017-05-31T02:07:07Z")

</div>

What values are you using on this site for

> <https://github.com/discourse/discourse_docker/blob/master/templates/web.ssl.template.yml#L22>

I’m hoping that if I have the same on my discourse site I should then be okay.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [May 31, 2017, 2:25am UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204/4 "2017-05-31T02:25:09Z")

</div>

I think this site is using to the default Discourse HTTPS configuration, but I’m not sure of that (maybe @jsha knows). The Mozilla configuration generator is likely to be a source of good advice, though: they’ve carefully researched exactly what client versions you’ll achieve compatibility with by taking their recommendations.

---

<div class="post-metadata">

**Author:** ![gchiu](https://avatars.discourse-cdn.com/v4/letter/g/96bed5/32.png) [@gchiu](https://community.letsencrypt.org/u/gchiu)\
**Post date:** [May 31, 2017, 3:32am UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204/5 "2017-05-31T03:32:07Z")

</div>

I also used the defaults for my discourse site but I only have 2 cipher suites for TLS 1.0 and your site has 4 so was wondering if the setting in the `web.ssl.template.yml` file were different to account for that.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [May 31, 2017, 5:54pm UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204/6 "2017-05-31T17:54:37Z")

</div>

We don’t directly manage the TLS config for this Discourse instance. We use Discourse’s hosted service.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [June 30, 2017, 5:54pm UTC](https://community.letsencrypt.org/t/configuring-older-cipher-suite-support-for-servers-mozilla-tls-config/35204/7 "2017-06-30T17:54:51Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
