Re: ssl: unsafe legacy renegotiation

SZÉPE Viktor <[email protected]> Thu, 09 Feb 2023 20:31:49 +0100
Newsgroups gmane.comp.monitoring.monit.general
Message-ID <[email protected]>
Idézem/Quoting sashk via This is the general mailing list for monit  
<[email protected]>:

> Hi,
>
>> Google the error and solution. Either update SSL on the cable modem  
>> “server” if you can or modify Monit (the client) yourself.
>
>
> Upgrading ssl is not possible on cable modem, therefore as I stated  
> in my original email:
>>>  It seems re-configuring OpenSSL it is possible to do systemwide,  
>>> but I would like to avoid doing so.
>
> I was hoping there is a way, similar to ssl options {version:  
> TLSV1,... } to enable this setting just for this particular check in  
> monit, not systemwide, as this opens system to CVE-2009-3555.
>
> Thanks.

Hello!
You can always install a small web proxy server.
e.g. https://github.com/tinyproxy/tinyproxy


SZÉPE Viktor, webes alkalmazás üzemeltetés / Running your application
https://github.com/szepeviktor/debian-server-tools/blob/master/CV.md
~~~
ügyelet 🌶️ hotline: +36-20-4242498  [email protected]  skype: szepe.viktor
Budapest, III. kerület
smime.p7s (application/pkcs7-signature, 6 KB) - not displayed