Sentora Support Forums
SSL 3.0 not secure - Printable Version

+- Sentora Support Forums (https://senforums.mach-hosting.com)
+-- Forum: General Forums - (Non-Sentora Support) (https://senforums.mach-hosting.com/forumdisplay.php?fid=1)
+--- Forum: General Discussions (Non-Support Related) (https://senforums.mach-hosting.com/forumdisplay.php?fid=2)
+--- Thread: SSL 3.0 not secure (/showthread.php?tid=452)



SSL 3.0 not secure - Me.B - 10-15-2014

http://googleonlinesecurity.blogspot.fr/2014/10/this-poodle-bites-exploiting-ssl-30.html

Google security team iunveiled a flaw in SSL 3.0.... NSA must be happy.

Details here:
https://www.openssl.org/~bodo/ssl-poodle.pdf

No solution unless switching fully to TLS.

M B


RE: SSL 3.0 not secure - jacobg830 - 10-15-2014

https://wiki.mozilla.org/Security/Server_Side_TLS provides some good information on configuring your server. Thanks for alerting me about this Smile


RE: SSL 3.0 not secure - Me.B - 10-15-2014

http://news.netcraft.com/archives/2014/10/15/googles-poodle-affects-oodles.html

stats & more infos.


RE: SSL 3.0 not secure - kandrews - 10-17-2014

I did a quick blog post over on zVPS : http://blog.zvps.uk/security/2014/10/15/poodle-sslv3-bleed-bug/ explains how users can protect themselves on browsers as well as server admins switching off sslv3 for apache/nginx/dovecot/postfix/nodejs etc Smile

We disabled sslv3 on our servers back in May after reading up on ssl security Smile