Sentora Support Forums

Full Version: SSL 3.0 not secure
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
http://googleonlinesecurity.blogspot.fr/...sl-30.html

Google security team iunveiled a flaw in SSL 3.0.... NSA must be happy.

Details here:
https://www.openssl.org/~bodo/ssl-poodle.pdf

No solution unless switching fully to TLS.

M B
https://wiki.mozilla.org/Security/Server_Side_TLS provides some good information on configuring your server. Thanks for alerting me about this Smile
I did a quick blog post over on zVPS : http://blog.zvps.uk/security/2014/10/15/...bleed-bug/ explains how users can protect themselves on browsers as well as server admins switching off sslv3 for apache/nginx/dovecot/postfix/nodejs etc Smile

We disabled sslv3 on our servers back in May after reading up on ssl security Smile