Re: Disabling SSLv3

Matthias Hunstock <[email protected]> Tue, 3 May 2016 09:33:25 +0200
Newsgroups gmane.mail.perdition.user
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------040107020005030108050800
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Am 02.05.2016 um 23:23 schrieb Simon Horman:
> * It is not at all clear to me that the patch above disables SSLv3.


No, that was a separate patch I think. Interesting that I do not find it
in my archive of this list :-/

I attached it for reference, but did not check, if it applies cleanly to
the current HEAD of perdition.



>   I believe a separate change to allow users to select which SSL/TLS
>   protocol versions are enabled may be worth adding to perdition.
>   But I'm not sure of a way to do that cleanly which doesn't require
>   updating perdition each time the underlying SSL/TLS implementation,
>   currently OpenSSL, adds support for a new protocol.

The protocol option should be a text string that is just given to
OpenSSL, so you do not need to change code for a new protocol... but the
whole thing does not really scale up and is no fun, just see the support
for Forward Secrecy. Everytime you want to use a new feature of OpenSSL
you have to integrate a bunch of options, configurations etc. to be able
to use those features.

It seems to me that OpenSSL addresses this issue with its Version 1.1,
the recent announcement sounded like there will finally be a kind of
separate configuration file just for the SSL. So all your software needs
to know as an option is something like "path to openSSL config file".

But there will be some time going by until OpenSSL 1.1 is available in
the distros...



Regards
Matthias


--=20
Dipl.-Inf. Matthias Hunstock
UniRZ der TU Ilmenau, Raum 07
Tel.: +49 3677 69-1289

--------------040107020005030108050800
Content-Type: text/plain; charset=UTF-8;
 name="no-ssl3-no-compression.patch"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
 filename="no-ssl3-no-compression.patch"

LS0tIHBlcmRpdGlvbi0xLjE5fnJjNS5vcmlnL3BlcmRpdGlvbi9zc2wuYworKysgcGVyZGl0
aW9uLTEuMTl+cmM1L3BlcmRpdGlvbi9zc2wuYwpAQCAtNjAyLDYgKzYwMiwxOSBAQCBTU0xf
Q1RYICpwZXJkaXRpb25fc3NsX2N0eChjb25zdCBjaGFyICpjCiAJfQogCiAJLyoKKwkgKiBT
ZXQgU2VydmVyIGNpcGhlciBvcmRlciBwcmVmZXJlbmNlIGFuZCBwcm90b2NvbHMKKwkgKi8K
KwlpZihmbGFnICYgUEVSRElUSU9OX1NTTF9TRVJWRVIpIHsKKwkJaWYoU1NMX0NUWF9zZXRf
b3B0aW9ucyhzc2xfY3R4LCBTU0xfT1BfTk9fU1NMdjIgfCBTU0xfT1BfTk9fU1NMdjMgfCBT
U0xfT1BfTk9fQ09NUFJFU1NJT04gfCBTU0xfT1BfQ0lQSEVSX1NFUlZFUl9QUkVGRVJFTkNF
KSA8IDApIHsKKwkJCVBFUkRJVElPTl9ERUJVR19TU0xfRVJSKCJTU0xfQ1RYX3NldF9vcHRp
b25zIik7CisJCX0KKwl9IGVsc2UgeworCQlpZihTU0xfQ1RYX3NldF9vcHRpb25zKHNzbF9j
dHgsIFNTTF9PUF9OT19TU0x2MiB8IFNTTF9PUF9OT19TU0x2MyB8IFNTTF9PUF9OT19DT01Q
UkVTU0lPTikgPCAwKSB7CisJCQlQRVJESVRJT05fREVCVUdfU1NMX0VSUigiU1NMX0NUWF9z
ZXRfb3B0aW9ucyIpOworCQl9CisJfQorCisJLyoKIAkgKiBTZXQgdGhlIGF2YWlsYWJsZSBj
aXBoZXJzCiAJICovCiAJaWYoY2lwaGVycyAmJiBTU0xfQ1RYX3NldF9jaXBoZXJfbGlzdChz
c2xfY3R4LCBjaXBoZXJzKSA8IDApIHsK
--------------040107020005030108050800
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXwpQZXJkaXRpb24t
dXNlcnMgbWFpbGluZyBsaXN0ClBlcmRpdGlvbi11c2Vyc0B2ZXJnZW5ldC5uZXQKaHR0cHM6Ly9s
aXN0cy52ZXJnZW5ldC5uZXQvbGlzdGluZm8vcGVyZGl0aW9uLXVzZXJzCg==

--------------040107020005030108050800--