Menu

#3899 strong PCI-compliant ciphers is not PCI Compliant

open
5
2011-04-25
2011-04-25
Anonymous
No

Even though I chose the new option Strong PCI-Compliant ciphers. The trustwave Audit system still lists these ciphers as being supported which apparently are not PCI compliant because they are used with SSLv2:
DES-CBC3-MD5
RC2-CBC-MD5
RC4-MD5
Using the option: HIGH:!SSLv2:!ADH:!aNULL:!eNULL:!NULL
Passes the PCI compliance check.

It would be nice if this was fixed and the same option added to usermin too.

Discussion


Log in to post a comment.

Auth0 Logo