old is a TLS security profile based on: 
https://wiki.mozilla.org/Security/Server_Side_TLS#Old_backward_compatibility 
and looks like this (yaml): 
  ciphers: 
    - TLS_AES_128_GCM_SHA256 
    - TLS_AES_256_GCM_SHA384 
    - TLS_CHACHA20_POLY1305_SHA256 
    - ECDHE-ECDSA-AES128-GCM-SHA256 
    - ECDHE-RSA-AES128-GCM-SHA256 
    - ECDHE-ECDSA-AES256-GCM-SHA384 
    - ECDHE-RSA-AES256-GCM-SHA384 
    - ECDHE-ECDSA-CHACHA20-POLY1305 
    - ECDHE-RSA-CHACHA20-POLY1305 
    - DHE-RSA-AES128-GCM-SHA256 
    - DHE-RSA-AES256-GCM-SHA384 
    - DHE-RSA-CHACHA20-POLY1305 
    - ECDHE-ECDSA-AES128-SHA256 
    - ECDHE-RSA-AES128-SHA256 
    - ECDHE-ECDSA-AES128-SHA 
    - ECDHE-RSA-AES128-SHA 
    - ECDHE-ECDSA-AES256-SHA384 
    - ECDHE-RSA-AES256-SHA384 
    - ECDHE-ECDSA-AES256-SHA 
    - ECDHE-RSA-AES256-SHA 
    - DHE-RSA-AES128-SHA256 
    - DHE-RSA-AES256-SHA256 
    - AES128-GCM-SHA256 
    - AES256-GCM-SHA384 
    - AES128-SHA256 
    - AES256-SHA256 
    - AES128-SHA 
    - AES256-SHA 
    - DES-CBC3-SHA 
  minTLSVersion: VersionTLS10  |