Hello everybody,
I discovered 'Hiawatha' this week and I want to say thank you for the development of this tool.
Would like to give some feedback, so you can perhaps continue improving the software.
1. I think it would be great if you could choose which ciphers you want to use and create a simple preference list. I know that there are already topics about this. But I don't really understand why this hasn't been implemented by now. I think only people with crypto-knowledge would change the default settings and to change the ssl.c-file isn't comfortable and not possible for non-programmers like me.
To change which ciphers are allowed to use would give more freedom to the user.
By the way: Is there a list where I can find all ciphers 'Hiawatha' is using?
2. I tested to use an encrypted private key for SSL so that I have to decrypt the key every time the webserver (re)starts. Unfortunately, it failed. Did I a mistake or is it not possible with 'Hiawatha'? Perhaps it could be a security feature which is useful for some people.
3. Has 'Hiawatha' already been audited and is there a report?
Thank you again for your work.
Syree
(Operating system: Linux)