Welcome! Log In Create A New Profile

Advanced

TLS Renegotiation / Man-in-the-Middle vulnerability?

Posted by joemastersemison 
TLS Renegotiation / Man-in-the-Middle vulnerability?
October 08, 2012 03:31PM
We switched to nginx earlier this year, and just had our first penetration test against it. One issue they found is that the our setup is vulnerable to the "TLS renegotiation man-in-the-middle vulnerability." (SSLv3 / TLSv1 renegotiation). I verified this separately by checking our site against https://www.ssllabs.com/ssltest/index.html ("Secure Renegotiation" is flagged in orange as a DoS danger).

The pen test firm has guides for how to address this issue with Apache and IIS and some other web servers, but not nginx.

We are running the latest stable (1.2.4).

Can anyone give advice on how to address this security issue? (They have flagged it as a "medium" issue, and we do want to clear all issues that are medium and above).
Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 87
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready