Last modified: 2013-09-09 18:35:27 UTC
NSA Suite B is a crypto suite that requires the usage of AES operating in GCM mode along with an elliptic curve DH key exchange. It allows for actually establishing a secure connection without running into the various BEAST, CRIME, etc. vulnerabilities in other TLS suites.
As promised in <http://lists.wikimedia.org/pipermail/wikimedia-l/2013-August/127463.html> I've enabled a GCM cipher via change <https://gerrit.wikimedia.org/r/#/c/83043/>.