[Cryptech Core] Poodles
Rob Austein
sra at hactrn.net
Thu Oct 16 01:37:50 UTC 2014
{bikeshed,git,lists,wiki,trac}.cryptech.is has been upgraded to
protect against the Poodle attack. User visible changes:
- SSLv3 is no longer supported on any TLS-based service
- Apache now uses its own TLS cipher suite preference ordering rather
than the client's (apparently some clients are too dumb to order
their own preference lists correctly, which can lead to gratuitous
downgrades to suites that don't support forward secrecy).
Please report any problems.
More information about the Core
mailing list