Default cipherlist contains HTTP/2 blacklisted ciphers (in first position)

Some people reported me not being able to connect to my HTTP/2 services running NGINX v1.11.6 mainline.

I have the option ssl_prefer_server_ciphers to 'on' for PFS, using NGINX default cipherlist. This is what made some strict browsers (compiled by hand, probably w/ some strict encryption perameters - AFAIK) stop being able to connect.

After proceeding a Qualys SSL Test, I got reported that some browsers got an HTTP/2 blacklisted cipher negotiated, with may break all encrypted connections on browsers that enforce a strict implementation of the HTTP/2 RFC.

The list of blacklisted ciphers on HTTP/2:
The passage from the RFC which points this out:

Of course, a fix to this is to set ssl_prefer_server_ciphers to 'off'. But it also break PFS enforcement, while NGINX still proposes blacklisted ciphers, which seems invalid according to specifications. Or, use a custom cipherlist. Though, the default NGINX configuration should come with a proper cipherlist regarding standards, so I suggest removing the blacklisted ciphers (see the first link I attached above).

The TLS1.2 cipherlist as reported by an nmap to my NGINX:

| TLSv1.2:
| ciphers:
| TLS_DHE_RSA_WITH_AES_128_CBC_SHA (dh 4096) - A
| TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 (dh 4096) - A
| TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (dh 4096) - A
| TLS_DHE_RSA_WITH_AES_256_CBC_SHA (dh 4096) - A
| TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 (dh 4096) - A
| TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (dh 4096) - A
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
| TLS_RSA_WITH_AES_128_CBC_SHA (rsa 4096) - A
| TLS_RSA_WITH_AES_128_CBC_SHA256 (rsa 4096) - A
| TLS_RSA_WITH_AES_128_GCM_SHA256 (rsa 4096) - A
| TLS_RSA_WITH_AES_256_CBC_SHA (rsa 4096) - A
| TLS_RSA_WITH_AES_256_CBC_SHA256 (rsa 4096) - A
| TLS_RSA_WITH_AES_256_GCM_SHA384 (rsa 4096) - A
| TLS_RSA_WITH_CAMELLIA_128_CBC_SHA (rsa 4096) - A
| TLS_RSA_WITH_CAMELLIA_256_CBC_SHA (rsa 4096) - A

Duplicate of #794.

