[Cryptech Core] Poodles

Rob Austein sra at hactrn.net
Thu Oct 16 01:37:50 UTC 2014


{bikeshed,git,lists,wiki,trac}.cryptech.is has been upgraded to
protect against the Poodle attack.  User visible changes:

- SSLv3 is no longer supported on any TLS-based service

- Apache now uses its own TLS cipher suite preference ordering rather
  than the client's (apparently some clients are too dumb to order
  their own preference lists correctly, which can lead to gratuitous
  downgrades to suites that don't support forward secrecy).

Please report any problems.



More information about the Core mailing list