Re: Disabling SSLv3

Xavi Garcia <[email protected]> Fri, 28 Aug 2015 17:54:27 +0200
Newsgroups gmane.mail.perdition.user
Message-ID <CAPonemzvL3PzFxWkG6WbKevSMTCAxy-KG3kmtkf+_LS-bCSJMQ@mail.gmail.com>
--===============0488241515==
Content-Type: multipart/alternative; boundary=047d7b3a8c603898b0051e611946

--047d7b3a8c603898b0051e611946
Content-Type: text/plain; charset=UTF-8

Hi,

I had to reconfigure perdition to listen only on localhost and then use
stunnel to do the TLS.

Kind regards,

Xavier Garcia
On Aug 28, 2015 17:31, "Epiontis IT" <[email protected]> wrote:

> Hello Xavier,
>
> did you have any success disabling SSLv3? I would like to disable any old
> ciphers and turn on Forward Secrecy. Do you have experience with this and
> perdition?
>
> Thank you,
> Alex
>
> From: Xavier Garcia <xavi.garcia <at> gmail.com>
> Subject: Re: Disabling SSLv3
> <http://news.gmane.org/find-root.php?message_id=20141031133121.GB53613%40beastie.ads.eso.org>
> Newsgroups: gmane.mail.perdition.user
> <http://news.gmane.org/gmane.mail.perdition.user>
> Date: 2014-10-31 13:31:23 GMT (43 weeks, 1 hour and 45 minutes ago)
>
> Hi,
>
> AFAIK, this enables STARTTLS in the port instead of starting a
> purely encrypted connection.
>
> nc -vv imapproxy01i 993
> Connection to imapproxy01i 993 port [tcp/imaps] succeeded!
> * OK [CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=REFERENCES
> * MULTIAPPEND UNSELECT LITERAL+ IDLE CHILDREN NAMESPACE
> * LOGIN-REFERRALS STARTTLS LOGINDISABLED] perdition ready on
> * imapproxy01i 00028de7
>
> I haven't tested but I think this may not change the list of
> accepted cyphers. After reading the manual and some messages in
> the list, it seems that all references to TLS in the
> configuration are aiming at STARTTLS and the only way to change
> the valid ciphers is with *ssl_listen_ciphers* and
> *ssl_outgoing_ciphers*. Am I mistaken?
>
> Regards,
>
> Xavier Garcia
>
> On Fri, Oct 31, 2014 at 02:10:42PM +0100, LE SAOUT Mael wrote:
> > Hi all,
> >
> > I have to disable it in /etc/sysconfig/perdition :
> > POP3S_FLAGS="--outgoing_port 110 --ssl_mode tls_listen,tls_listen_force"
> > IMAP4S_FLAGS="--outgoing_port 143 --ssl_mode tls_listen,tls_listen_force"
> >
> > Hope it will help you.
> >
> > Regards
> >
> > Mael
> >
> > -----Message d'origine-----
> > De?: perdition-users-bounces <at> vergenet.net [mailto:perdition-users-bounces <perdition-users-bounces> <at> vergenet.net] De la
> part de Xavier Garcia
> > Envoy??: vendredi 31 octobre 2014 13:59
> > ??: perdition-users <at> vergenet.net
> > Objet?: [PERDITION-USERS] Disabling SSLv3
> >
> > Dear all,
> >
> > I am trying to disable SSLv3  on perdition 2.0-1.x86_64 It is running in a RHEL 6.5 clone and it was compiled
> with the SPEC files.
> >
> > In theory, I should apply the following configuration but it also disables TLSv1 and TLSv1.1, being
> TLSv1.2 still available.
> >
> > ---
> > ssl_listen_ciphers "ALL:!SSLv2:!SSLv3"
> > ---
> >
> > I don't know much about cryptography but I guess it makes sense because I obtain the same result in all my
> boxes (RHEL 6.5 , Fedora and FreeBSD 10) when I execute:
> >
> > openssl ciphers -v 'ALL:!SSLv2:!SSLv3'
> >
> >
> > What would be the best way to disable SSLv2 and SSLv3 for incoming and outgoing connections?
> >
> > Regards,
> >
> > Xavier Garcia
> > ______________________________________________
> > Perdition-users mailing list
> > Perdition-users <at> vergenet.net
> > http://lists.vergenet.net/listinfo/perdition-users
> >
> > ----
>
> ______________________________________________
> Perdition-users mailing list
> Perdition-users <at> vergenet.nethttp://lists.vergenet.net/listinfo/perdition-users
>
>
> ______________________________________________
> Perdition-users mailing list
> [email protected]
> http://lists.vergenet.net/listinfo/perdition-users
>
>

--047d7b3a8c603898b0051e611946
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<p dir=3D"ltr">Hi,</p>
<p dir=3D"ltr">I had to reconfigure perdition to listen only on localhost a=
nd then use stunnel to do the TLS.</p>
<p dir=3D"ltr">Kind regards,</p>
<p dir=3D"ltr">Xavier Garcia</p>
<div class=3D"gmail_quote">On Aug 28, 2015 17:31, &quot;Epiontis IT&quot; &=
lt;<a href=3D"mailto:[email protected]">it_mailinglists@epiontis=
.com</a>&gt; wrote:<br type=3D"attribution"><blockquote class=3D"gmail_quot=
e" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
 =20

   =20
 =20
  <div bgcolor=3D"#FFFFFF" text=3D"#000000">
    Hello Xavier,<br>
    <br>
    did you have any success disabling SSLv3? I would like to disable
    any old ciphers and turn on Forward Secrecy. Do you have experience
    with this and perdition?<br>
    <br>
    Thank you,<br>
    Alex<br>
    <br>
    From: Xavier Garcia &lt;xavi.garcia &lt;at&gt; <a href=3D"http://gmail.=
com" target=3D"_blank">gmail.com</a>&gt;<br>
    Subject: <a rel=3D"nofollow" href=3D"http://news.gmane.org/find-root.ph=
p?message_id=3D20141031133121.GB53613%40beastie.ads.eso.org" target=3D"_bla=
nk">Re:
      Disabling SSLv3</a><br>
    Newsgroups: <a href=3D"http://news.gmane.org/gmane.mail.perdition.user"=
 target=3D"_blank">gmane.mail.perdition.user</a><br>
    Date: 2014-10-31 13:31:23 GMT (43 weeks, 1 hour and 45 minutes ago)<br>
    <pre>Hi,

AFAIK, this enables STARTTLS in the port instead of starting a
purely encrypted connection.

nc -vv imapproxy01i 993
Connection to imapproxy01i 993 port [tcp/imaps] succeeded!
* OK [CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=3DREFERENCES
* MULTIAPPEND UNSELECT LITERAL+ IDLE CHILDREN NAMESPACE
* LOGIN-REFERRALS STARTTLS LOGINDISABLED] perdition ready on
* imapproxy01i 00028de7

I haven&#39;t tested but I think this may not change the list of
accepted cyphers. After reading the manual and some messages in
the list, it seems that all references to TLS in the
configuration are aiming at STARTTLS and the only way to change
the valid ciphers is with *ssl_listen_ciphers* and
*ssl_outgoing_ciphers*. Am I mistaken?

Regards,

Xavier Garcia

On Fri, Oct 31, 2014 at 02:10:42PM +0100, LE SAOUT Mael wrote:
&gt; Hi all,
&gt;=20
&gt; I have to disable it in /etc/sysconfig/perdition :
&gt; POP3S_FLAGS=3D&quot;--outgoing_port 110 --ssl_mode tls_listen,tls_list=
en_force&quot;
&gt; IMAP4S_FLAGS=3D&quot;--outgoing_port 143 --ssl_mode tls_listen,tls_lis=
ten_force&quot;
&gt;=20
&gt; Hope it will help you.
&gt;=20
&gt; Regards
&gt;=20
&gt; Mael
&gt;=20
&gt; -----Message d&#39;origine-----
&gt; De?: perdition-users-bounces &lt;at&gt; <a href=3D"http://vergenet.net=
" target=3D"_blank">vergenet.net</a> [<a href=3D"mailto:perdition-users-bou=
nces" target=3D"_blank">mailto:perdition-users-bounces</a> &lt;at&gt; <a hr=
ef=3D"http://vergenet.net" target=3D"_blank">vergenet.net</a>] De la
part de Xavier Garcia
&gt; Envoy??: vendredi 31 octobre 2014 13:59
&gt; ??: perdition-users &lt;at&gt; <a href=3D"http://vergenet.net" target=
=3D"_blank">vergenet.net</a>
&gt; Objet?: [PERDITION-USERS] Disabling SSLv3
&gt;=20
&gt; Dear all,
&gt;=20
&gt; I am trying to disable SSLv3  on perdition 2.0-1.x86_64 It is running =
in a RHEL 6.5 clone and it was compiled
with the SPEC files.
&gt;=20
&gt; In theory, I should apply the following configuration but it also disa=
bles TLSv1 and TLSv1.1, being
TLSv1.2 still available.
&gt;=20
&gt; ---
&gt; ssl_listen_ciphers &quot;ALL:!SSLv2:!SSLv3&quot;
&gt; ---
&gt;=20
&gt; I don&#39;t know much about cryptography but I guess it makes sense be=
cause I obtain the same result in all my
boxes (RHEL 6.5 , Fedora and FreeBSD 10) when I execute:
&gt;=20
&gt; openssl ciphers -v &#39;ALL:!SSLv2:!SSLv3&#39;
&gt;=20
&gt;=20
&gt; What would be the best way to disable SSLv2 and SSLv3 for incoming and=
 outgoing connections?
&gt;=20
&gt; Regards,
&gt;=20
&gt; Xavier Garcia
&gt; ______________________________________________
&gt; Perdition-users mailing list
&gt; Perdition-users &lt;at&gt; <a href=3D"http://vergenet.net" target=3D"_=
blank">vergenet.net</a>
&gt; <a rel=3D"nofollow" href=3D"http://lists.vergenet.net/listinfo/perditi=
on-users" target=3D"_blank">http://lists.vergenet.net/listinfo/perdition-us=
ers</a>
&gt;=20
&gt; ----
</pre>
    <pre>______________________________________________
Perdition-users mailing list
Perdition-users &lt;at&gt; <a href=3D"http://vergenet.net" target=3D"_blank=
">vergenet.net</a>
<a rel=3D"nofollow" href=3D"http://lists.vergenet.net/listinfo/perdition-us=
ers" target=3D"_blank">http://lists.vergenet.net/listinfo/perdition-users</=
a>
</pre>
  </div>

<br>______________________________________________<br>
Perdition-users mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]=
t</a><br>
<a href=3D"http://lists.vergenet.net/listinfo/perdition-users" rel=3D"noref=
errer" target=3D"_blank">http://lists.vergenet.net/listinfo/perdition-users=
</a><br>
<br></blockquote></div>

--047d7b3a8c603898b0051e611946--

--===============0488241515==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXwpQZXJkaXRpb24t
dXNlcnMgbWFpbGluZyBsaXN0ClBlcmRpdGlvbi11c2Vyc0B2ZXJnZW5ldC5uZXQKaHR0cDovL2xp
c3RzLnZlcmdlbmV0Lm5ldC9saXN0aW5mby9wZXJkaXRpb24tdXNlcnMK

--===============0488241515==--