I have been attempting to configure my site to have http/2 support, but I kept having to remove cipher suites because of the blacklist. Eventually, I got the list whittled down sufficiently.
The problem, however, is that I only have a cipher suite compatible with TLS 1.2 now. I'd love to use this, but it's not practical as it breaks Safari versions as new as shipping with OS X 10.10 because those only support CBC suites.
Any thoughts as to what to do to have reasonable compatibility, yet support HTTP/2?
Presently, the list is AESGCM+EECDH:AESGCM+EDH:!SHA1:!DSS:!DSA:!ECDSA:!aNULL