[global] override-mode = allowlist [overrides] secure-hash = SHA256 secure-hash = SHA384 secure-hash = SHA512 secure-hash = SHA224 secure-hash = SHA3-256 secure-hash = SHA3-384 secure-hash = SHA3-512 secure-hash = SHAKE-256 tls-enabled-mac = AEAD tls-enabled-mac = SHA512 tls-enabled-group = GROUP-SECP256R1 tls-enabled-group = GROUP-SECP521R1 tls-enabled-group = GROUP-SECP384R1 tls-enabled-group = GROUP-FFDHE2048 tls-enabled-group = GROUP-FFDHE3072 tls-enabled-group = GROUP-FFDHE4096 tls-enabled-group = GROUP-FFDHE6144 tls-enabled-group = GROUP-FFDHE8192 secure-sig = ECDSA-SHA3-256 secure-sig = ECDSA-SHA256 secure-sig = ECDSA-SECP256R1-SHA256 secure-sig = ECDSA-SHA3-384 secure-sig = ECDSA-SHA384 secure-sig = ECDSA-SECP384R1-SHA384 secure-sig = ECDSA-SHA3-512 secure-sig = ECDSA-SHA512 secure-sig = ECDSA-SECP521R1-SHA512 secure-sig = RSA-PSS-SHA256 secure-sig = RSA-PSS-SHA384 secure-sig = RSA-PSS-SHA512 secure-sig = RSA-PSS-RSAE-SHA256 secure-sig = RSA-PSS-RSAE-SHA384 secure-sig = RSA-PSS-RSAE-SHA512 secure-sig = RSA-SHA3-256 secure-sig = RSA-SHA256 secure-sig = RSA-SHA3-384 secure-sig = RSA-SHA384 secure-sig = RSA-SHA3-512 secure-sig = RSA-SHA512 secure-sig = ECDSA-SHA224 secure-sig = RSA-SHA224 secure-sig-for-cert = ECDSA-SHA3-256 secure-sig-for-cert = ECDSA-SHA256 secure-sig-for-cert = ECDSA-SECP256R1-SHA256 secure-sig-for-cert = ECDSA-SHA3-384 secure-sig-for-cert = ECDSA-SHA384 secure-sig-for-cert = ECDSA-SECP384R1-SHA384 secure-sig-for-cert = ECDSA-SHA3-512 secure-sig-for-cert = ECDSA-SHA512 secure-sig-for-cert = ECDSA-SECP521R1-SHA512 secure-sig-for-cert = RSA-PSS-SHA256 secure-sig-for-cert = RSA-PSS-SHA384 secure-sig-for-cert = RSA-PSS-SHA512 secure-sig-for-cert = RSA-PSS-RSAE-SHA256 secure-sig-for-cert = RSA-PSS-RSAE-SHA384 secure-sig-for-cert = RSA-PSS-RSAE-SHA512 secure-sig-for-cert = RSA-SHA3-256 secure-sig-for-cert = RSA-SHA256 secure-sig-for-cert = RSA-SHA3-384 secure-sig-for-cert = RSA-SHA384 secure-sig-for-cert = RSA-SHA3-512 secure-sig-for-cert = RSA-SHA512 secure-sig-for-cert = ECDSA-SHA224 secure-sig-for-cert = RSA-SHA224 enabled-curve = SECP256R1 enabled-curve = SECP521R1 enabled-curve = SECP384R1 tls-enabled-cipher = AES-256-GCM tls-enabled-cipher = AES-256-CCM tls-enabled-cipher = AES-128-GCM tls-enabled-cipher = AES-128-CCM tls-enabled-kx = ECDHE-RSA tls-enabled-kx = ECDHE-ECDSA tls-enabled-kx = DHE-RSA enabled-version = TLS1.3 enabled-version = TLS1.2 enabled-version = DTLS1.2 tls-session-hash = require min-verification-profile = medium [priorities] SYSTEM=NONE