Re: check_pop plugin poodle vulnerability

B <[email protected]> Mon, 20 Oct 2014 13:05:26 +0800
Newsgroups gmane.network.nagios.plugins
Message-ID <BLU436-SMTP1982D9CBD545014465756FDCD970__40642.6120935523$1413781545$gmane$org@phx.gbl>
You need to make sure your server returns tls1.0 first. Then, check if 
your plugin supports it. Supposedly, your server is not the problem. The 
assumption is that your plugin doesn't support it. You can run verbose 
seeing how it goes.

-B
On 10/19/2014 9:43 PM, Andrew Nemeth wrote:
> Hello,
>
> We recently disabled SSLv3 and SSLv2 due to the poodle and other
> vulnerabilities however the plugins (both smtps and pop3s plugins) are now
> failing with the following:
>
> root@estonia:/usr/local/nagios/etc/check_multi#
> /usr/local/nagios/libexec/check_spop -a 184.170.132.66
> CRITICAL - Cannot make SSL connection
> 12515:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert
> handshake failure:s23_clnt.c:596:
>
> Could you advise how we can check against TLS instead?
>
> Thank you,
>
> Andrew
>