Mulberry, SSLv3 and POODLE
Christer Mjellem Strand <[email protected]> Sat, 18 Oct 2014 17:49:08 +0200
| Newsgroups | gmane.mail.mulberry.user |
|---|---|
| Message-ID | <F3DD2CA80AFA13C425B7B9F6@plopp> |
Greetings, As I'm sure you've all heard, this week's OpenSSL POODLE[1] vulnerability has caused sysadmins worldwide to scramble to disable SSLv3 on their servers. Although in the bigger picture this is probably a good thing, for Mulberry it causes a bit of trouble, since it supports TLS with STARTTLS, but otherwise only SSLv3 and SSLv23. Most IMAP and SMTP servers thankfully support STARTTLS, but no such luck with CalDAV, CardDAV or LDAP. In order to continue remaining functional, Mulberry will have to work with TLSv1. Ideally it should simply use the system OpenSSL libs without too much magic inbetween (which could allow for TLSv12, elliptic curve and such nice things), but at a bare minimum, TLSv1 needs to work. Anyone else hit by this? Anyone already working on it? Anyone up for the task? (I am not a developer, unfortunately) [1] <http://poodlebleed.com/> -- -==- -=- -==- Christer Mjellem Strand yitzhaq System administrator ICQ: 9557698 GSM: +47 922 000 12 JID: [email protected] -==- -=- -==-