Mulberry, SSLv3 and POODLE

Christer Mjellem Strand <[email protected]> Sat, 18 Oct 2014 17:49:08 +0200
Newsgroups gmane.mail.mulberry.user
Message-ID <F3DD2CA80AFA13C425B7B9F6@plopp>
Greetings,

As I'm sure you've all heard, this week's OpenSSL POODLE[1] 
vulnerability has caused sysadmins worldwide to scramble to disable 
SSLv3 on their servers. Although in the bigger picture this is probably 
a good thing, for Mulberry it causes a bit of trouble, since it 
supports TLS with STARTTLS, but otherwise only SSLv3 and SSLv23. Most 
IMAP and SMTP servers thankfully support STARTTLS, but no such luck 
with CalDAV, CardDAV or LDAP.

In order to continue remaining functional, Mulberry will have to work 
with TLSv1. Ideally it should simply use the system OpenSSL libs 
without too much magic inbetween (which could allow for TLSv12, 
elliptic curve and such nice things), but at a bare minimum, TLSv1 
needs to work.

Anyone else hit by this? Anyone already working on it? Anyone up for 
the task?

(I am not a developer, unfortunately)

[1] <http://poodlebleed.com/>

-- 
  -==-                  -=-                  -==-
   Christer Mjellem Strand               yitzhaq
   System administrator             ICQ: 9557698
   GSM: +47 922 000 12    JID: [email protected]
  -==-                  -=-                  -==-