Browse Source

Remove obsolete TLS v1.0 support

Alexandros Ioannides 6 years ago
parent
commit
c0eea557ed
1 changed files with 5 additions and 0 deletions
  1. 5 0
      install/upgrade/versions/1.0.3.sh

+ 5 - 0
install/upgrade/versions/1.0.3.sh

@@ -18,6 +18,11 @@ mv /etc/ssl/dhparam.pem $HESTIA_BACKUP/conf/
 cp -rf $HESTIA/install/deb/ssl/dhparam.pem /etc/ssl/
 cp -rf $HESTIA/install/deb/ssl/dhparam.pem /etc/ssl/
 systemctl reload nginx
 systemctl reload nginx
 
 
+# Enhance Vsftpd security
+echo "(*) Enhancing Vsftpd security..."
+cp -rf /etc/vsftpd.conf $HESTIA_BACKUP/conf/
+sed -i "s|ssl_tlsv1=YES|ssl_tlsv1=NO|g" /etc/vsftpd.conf
+
 # Enhance Dovecot security
 # Enhance Dovecot security
 echo "(*) Enhancing Dovecot security..."
 echo "(*) Enhancing Dovecot security..."
 mv /etc/dovecot/conf.d/10-ssl.conf $HESTIA_BACKUP/conf/
 mv /etc/dovecot/conf.d/10-ssl.conf $HESTIA_BACKUP/conf/