allow_tls10 = false allow_tls11 = false allow_tls12 = true allow_dtls10 = false allow_dtls12 = false ciphers = AES-128/GCM macs = AEAD signature_hashes = SHA-256 signature_methods = ECDSA key_exchange_methods = ECDH ecc_curves = secp256r1 allow_insecure_renegotiation = false include_time_in_hello_random = true allow_server_initiated_renegotiation = false hide_unknown_users = false server_uses_own_ciphersuite_preferences = true negotiate_encrypt_then_mac = true session_ticket_lifetime = 86400 dh_group = modp/ietf/2048 minimum_dh_group_size = 1024 minimum_ecdh_group_size = 255 minimum_rsa_bits = 2048 minimum_signature_strength = 128