Re: Disabling SSLv3
Matthias Hunstock <[email protected]> Tue, 3 May 2016 09:33:25 +0200
| Newsgroups | gmane.mail.perdition.user |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------040107020005030108050800 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Am 02.05.2016 um 23:23 schrieb Simon Horman: > * It is not at all clear to me that the patch above disables SSLv3. No, that was a separate patch I think. Interesting that I do not find it in my archive of this list :-/ I attached it for reference, but did not check, if it applies cleanly to the current HEAD of perdition. > I believe a separate change to allow users to select which SSL/TLS > protocol versions are enabled may be worth adding to perdition. > But I'm not sure of a way to do that cleanly which doesn't require > updating perdition each time the underlying SSL/TLS implementation, > currently OpenSSL, adds support for a new protocol. The protocol option should be a text string that is just given to OpenSSL, so you do not need to change code for a new protocol... but the whole thing does not really scale up and is no fun, just see the support for Forward Secrecy. Everytime you want to use a new feature of OpenSSL you have to integrate a bunch of options, configurations etc. to be able to use those features. It seems to me that OpenSSL addresses this issue with its Version 1.1, the recent announcement sounded like there will finally be a kind of separate configuration file just for the SSL. So all your software needs to know as an option is something like "path to openSSL config file". But there will be some time going by until OpenSSL 1.1 is available in the distros... Regards Matthias --=20 Dipl.-Inf. Matthias Hunstock UniRZ der TU Ilmenau, Raum 07 Tel.: +49 3677 69-1289 --------------040107020005030108050800 Content-Type: text/plain; charset=UTF-8; name="no-ssl3-no-compression.patch" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="no-ssl3-no-compression.patch" LS0tIHBlcmRpdGlvbi0xLjE5fnJjNS5vcmlnL3BlcmRpdGlvbi9zc2wuYworKysgcGVyZGl0 aW9uLTEuMTl+cmM1L3BlcmRpdGlvbi9zc2wuYwpAQCAtNjAyLDYgKzYwMiwxOSBAQCBTU0xf Q1RYICpwZXJkaXRpb25fc3NsX2N0eChjb25zdCBjaGFyICpjCiAJfQogCiAJLyoKKwkgKiBT ZXQgU2VydmVyIGNpcGhlciBvcmRlciBwcmVmZXJlbmNlIGFuZCBwcm90b2NvbHMKKwkgKi8K KwlpZihmbGFnICYgUEVSRElUSU9OX1NTTF9TRVJWRVIpIHsKKwkJaWYoU1NMX0NUWF9zZXRf b3B0aW9ucyhzc2xfY3R4LCBTU0xfT1BfTk9fU1NMdjIgfCBTU0xfT1BfTk9fU1NMdjMgfCBT U0xfT1BfTk9fQ09NUFJFU1NJT04gfCBTU0xfT1BfQ0lQSEVSX1NFUlZFUl9QUkVGRVJFTkNF KSA8IDApIHsKKwkJCVBFUkRJVElPTl9ERUJVR19TU0xfRVJSKCJTU0xfQ1RYX3NldF9vcHRp b25zIik7CisJCX0KKwl9IGVsc2UgeworCQlpZihTU0xfQ1RYX3NldF9vcHRpb25zKHNzbF9j dHgsIFNTTF9PUF9OT19TU0x2MiB8IFNTTF9PUF9OT19TU0x2MyB8IFNTTF9PUF9OT19DT01Q UkVTU0lPTikgPCAwKSB7CisJCQlQRVJESVRJT05fREVCVUdfU1NMX0VSUigiU1NMX0NUWF9z ZXRfb3B0aW9ucyIpOworCQl9CisJfQorCisJLyoKIAkgKiBTZXQgdGhlIGF2YWlsYWJsZSBj aXBoZXJzCiAJICovCiAJaWYoY2lwaGVycyAmJiBTU0xfQ1RYX3NldF9jaXBoZXJfbGlzdChz c2xfY3R4LCBjaXBoZXJzKSA8IDApIHsK --------------040107020005030108050800 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXwpQZXJkaXRpb24t dXNlcnMgbWFpbGluZyBsaXN0ClBlcmRpdGlvbi11c2Vyc0B2ZXJnZW5ldC5uZXQKaHR0cHM6Ly9s aXN0cy52ZXJnZW5ldC5uZXQvbGlzdGluZm8vcGVyZGl0aW9uLXVzZXJzCg== --------------040107020005030108050800--