Uploaded image for project: 'Traffic Server'
  1. Traffic Server
  2. TS-4247

Should no longer allow SSLv2 configuration

    XMLWordPrintableJSON

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Blocker
    • Resolution: Resolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Security, SSL
    • Labels:
      None

      Description

      In light of today's DROWN TLS vulnerability (CVE-2016-0800 and CVE-2016-0703 ), we should no longer have an option to allow an admin to configure SSLv2 (whether intentional or not, or just out of ignorance). The consequences are far too severe. This is also the only solution for CVE-2016-0800.

      Some details:
      https://drownattack.com/

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                davet Dave Thompson
                Reporter:
                davet Dave Thompson
              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: