默认情况下,全局接受和建议策略会激活某些安全协议和密码套件。
Horizon LDAP 中的对象路径 cn=common,ou=global,ou=properties,dc=vdi,dc=horizon,dc=internal 下提供了安全性相关设置。
默认全局接受策略
| 默认安全协议 |
默认密码套件 | 默认签名方案 |
TLS 1.3
注意:从 Horizon 2312.1 版本开始,这是首选协议。
|
- TLS_AES_128_GCM_SHA256
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256(2503 及更高版本)
|
- rsa_pss_rsae_sha512
- rsa_pss_rsae_sha384
- rsa_pss_rsae_sha256
- rsa_pss_pss_sha512
- rsa_pss_pss_sha384
- rsa_pss_pss_sha256
- rsa_pkcs1_sha512
- rsa_pkcs1_sha384
- rsa_pkcs1_sha256
- rsa_pkcs1_sha1
|
|
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256(2503 及更高版本)
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
|
- rsa_pss_rsae_sha512
- rsa_pss_rsae_sha384
- rsa_pss_rsae_sha256
- rsa_pss_pss_sha512
- rsa_pss_pss_sha384
- rsa_pss_pss_sha256
- rsa_pkcs1_sha512
- rsa_pkcs1_sha384
- rsa_pkcs1_sha256
- rsa_pkcs1_sha1
|
默认全局建议策略
| 默认安全协议 | 默认密码套件 | 默认签名方案 |
TLS 1.3
注意:从 Horizon 2312.1 版本开始,这是首选协议。
|
- TLS_AES_128_GCM_SHA256
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256(2503 及更高版本)
|
- rsa_pss_rsae_sha512
- rsa_pss_rsae_sha384
- rsa_pss_rsae_sha256
- rsa_pss_pss_sha512
- rsa_pss_pss_sha384
- rsa_pss_pss_sha256
- rsa_pkcs1_sha512
- rsa_pkcs1_sha384
- rsa_pkcs1_sha256
- rsa_pkcs1_sha1
- ecdsa_secp521r1_sha512
- ecdsa_secp384r1_sha384
- ecdsa_secp256r1_sha256
|
|
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256(2503 及更高版本)
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
|
- rsa_pss_rsae_sha512
- rsa_pss_rsae_sha384
- rsa_pss_rsae_sha256
- rsa_pss_pss_sha512
- rsa_pss_pss_sha384
- rsa_pss_pss_sha256
- rsa_pkcs1_sha512
- rsa_pkcs1_sha384
- rsa_pkcs1_sha256
- rsa_pkcs1_sha1
- ecdsa_secp521r1_sha512
- ecdsa_secp384r1_sha384
- ecdsa_secp256r1_sha256
|
默认全局通用策略
| 默认命名组 |
- secp384r1
- secp256r1
- secp521r1
- ffdhe2048
- ffdhe3072
- ffdhe4096
- ffdhe6144
- ffdhe8192
|
**注意:**在 FIPS 模式下,仅 GCM 密码套件和 TLS 1.2 处于激活状态。