This is the haproxy cipher list Snapt is most likely going to roll out next:


If you are using haproxy for SSL termination it’s a good idea to manually specify a cipher list to prevent attacks like BEAST, or other protocol weaknesses.

  1. I’m using:

    ssl-default-bind-ciphers AES:ALL:!aNULL:!eNULL:!DES:!RC4:!DHE:!EDH:!MD5:!PSK:!aECDH:@STRENGTH

    This gives an A+ SSL Labs rating for haproxy along with IE6 support with TLS 1.0 enabled.

    Hope this helps

