Welcome! Log In Create A New Profile

Advanced

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin
October 30, 2014 11:28AM
Hello!

On Thu, Oct 30, 2014 at 03:05:18PM +0100, Richard Fussenegger wrote:

> The rationale may make sense depending on the priorities, but shouldn't the
> default configuration target generic applications? Generic applications
> don't need compatibility with ancient software (only IE6 on XP actually
> /needs/ SSLv3, don't know about libraries though).

That's excatly the point: the default is for generic case, and in
general there is nothing wrong with supporting SSLv3 as long as
nothing better is available. And there are various clients which
don't support anything better, including IE6 on XP.

The bad thing with POODLE is actually that due to fallback code in
browsers it used to affect modern browsers. This problem goes
away gradually.

> Administrators who need the support can still enable it and make use of
> SCSV. And don't forget that 'modern browser' applies to IE up to 11, FF up
> to 34, Chrome up to ? (couldn't find the exact version) of which actually
> not a single one has SCSV support and they won't get it! Providing

As of now, the problem doesn't affect at least:

- latest versions of Chrome (TLS_FALLBACK_SCSV);

- latest versions of Opera (TLS_FALLBACK_SCSV, anti-POODLE record
splitting);

- latest versions of Safari (no block ciphers over SSLv3);

- latest (upcoming?) versions of Firefox (disabled fallback to
SSLv3);

- upcoming versions of IE (announced plans to disable fallback to
SSLv3).

This basically covers all modern browsers (or at least almost
all). Talking about not updated versions from security point of
view is mostly pointless, as there are multiple security problems
fixed on a regular basis, and not updated means not secure.

--
Maxim Dounin
http://nginx.org/

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH] SSL: don't enable SSLv3 by default

Piotr Sikora 976 October 30, 2014 12:18AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 579 October 30, 2014 09:48AM

Re: [PATCH] SSL: don't enable SSLv3 by default Attachments

Richard Fussenegger 529 October 30, 2014 10:08AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 646 October 30, 2014 11:28AM

Re: [PATCH] SSL: don't enable SSLv3 by default Attachments

Richard Fussenegger 586 October 30, 2014 11:32AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 542 October 30, 2014 11:48AM

Re: [PATCH] SSL: don't enable SSLv3 by default Attachments

Richard Fussenegger 563 October 30, 2014 11:56AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Piotr Sikora 750 October 30, 2014 07:34PM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 553 October 31, 2014 12:26AM

Re: [PATCH] SSL: don't enable SSLv3 by default

nginxorg 1015 October 31, 2014 09:36AM



Sorry, you do not have permission to post/reply in this forum.

Online Users

BMX
Guests: 118
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready