From: Dave I. <dav...@en...> - 2007-03-27 20:56:22
|
Well, it doesn't appear to be working :-( Try it yourself: Set ssl_version=3D10 and turn off SSL 3.0 and TLS 1.0 = in IE7 (Tools > Internet Options > Advanced), and see if you can connect. I can, but I would be interested in what other people experience. Thanks Dave I -----Original Message----- From: web...@li... [mailto:web...@li...] On Behalf Of Jamie Cameron Sent: Tuesday, March 27, 2007 4:01 PM To: Webmin users list Subject: Re: [webmin-l] SSL version used with miniserv On 27/Mar/2007 08:07 Dave Isaacs wrote .. > We have had some complaints that the miniserv web server supports SSL=20 > 2.0, which is considered a weak encryption protocol. Looking into this > I discovered the ssl_version configuration setting in miniserv.conf,=20 > so I specified ssl_version=3D10. This should have specified to = support=20 > only TLS version 1.0. I then restarted webmin. >=20 > To test this out I disabled TLS and SSL 3.0 support on my Firefox,=20 > Netscape, and IE7 browsers. Firefox reacts as expected: it will not=20 > connect to the webmin server. But Netscape and IE7 both still=20 > connect, and show SSL 2.0 as the protocol being used. >=20 > Have I misinterpreted the use of the ssl_version setting? Or is there=20 > a bug in the use of SSLeay that still allows unselected ssl versions=20 > to be used (though that wouldn't explain why Firefox is behaving). Hi Dave, The ssl_version option should set the version that SSLeay will accept only. Unfortunately I don't know what it does internally with this setting, but the docs say that it should work :-) > Thanks >=20 > Dave Isaacs >=20 > BTW, the customer in question is using Webmin 1.290 (they can't=20 > upgrade until later this year). I don't know if that makes a=20 > difference? Version 1.290 does support this option in just the same way as later versions.. - Jamie ------------------------------------------------------------------------ - Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys-and earn cash http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3D= DEVDE V - Forwarded by the Webmin mailing list at web...@li... To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list |