Menu

#4590 TLS renegotiation vulnerability webmin

1.740
open
nobody
None
1
2017-02-11
2015-04-27
Balakrishna
No

Hi,

Due to recent ssl and tls renegotiation vulnerabilities we were able to address ssl with ssl3 disable but how to fix tls renegotiated as this is the only left supported ssl now

Discussion

  • Balakrishna

    Balakrishna - 2015-04-27

    Tls renegotiation vulnerability

     
  • Jamie Cameron

    Jamie Cameron - 2015-04-27

    Can you provide some more details on this vulnerability?

    Recent versions of Webmin disable old SSL versions by default on new installs.

     
    • Balakrishna

      Balakrishna - 2015-05-13

      does it support TLS v1.2?

       
  • Balakrishna

    Balakrishna - 2015-05-13

    we need urgently to close TLSv1.0 findings on webmin.
    the latest version does address?

     
    • Balakrishna

      Balakrishna - 2015-05-13

      any update?

       
  • Jamie Cameron

    Jamie Cameron - 2015-05-14

    Yes, the 1.750 release of Webmin lets you disable older SSL versions at Webmin -> Webmin Configuration -> SSL Encryption.

     
  • Balakrishna

    Balakrishna - 2015-05-14

    does it support TLS 1.2?

     
  • Jamie Cameron

    Jamie Cameron - 2015-05-14

    If you disable SSL versions 2 and 3, only TLS 1.2 will remain.

     
  • Balakrishna

    Balakrishna - 2015-05-26

    I only need TLS1.2.
    If I disabled SSLv2,v3 the version it does show TLS1.0.
    I only want to have TLS 1.2.

    Please advise

     
  • Balakrishna

    Balakrishna - 2015-05-27

    can advise please...

     
  • Jamie Cameron

    Jamie Cameron - 2015-05-27

    So right now in Webmin there is no option to disable TLS 1.0, 1.1 or 1.2 entirely.

    However, it may be possible to do what you want via the cipher list. Which specific vulnerability are you looking to defend against?

     
  • Balakrishna

    Balakrishna - 2015-05-28

    The remote service encrypts traffic using TLS / SSL but allows a client to insecurely renegotiate the connection after the initial handshake. An unauthenticated, remote attacker may be able to leverage this issue to inject an arbitrary amount of plaintext into the beginning of the application protocol stream, which could facilitate man-in-the-middle attacks if the service assumes that the sessions before and after renegotiation are from the same 'client' and merges them at the application layer.

    CVE : CVE-2009-3555

    tcp 10000
    TLSv1 supports insecure renegotiation.

     
  • Balakrishna

    Balakrishna - 2015-05-28

    can you advise if there is any fix released or config update needed for this?

     
  • Jamie Cameron

    Jamie Cameron - 2015-05-28

    Ok, I have checked in this fix https://github.com/webmin/webmin/commit/2b77e8f020f3dabab059694f7045a9ae59ee28fd to add options to disable TLS v1, 1.1 or 1.2. These should all you to disable this vulnerability.

    That's a pretty old CVE though - does it rely on the client only making a TLS v1 connection in the first place?

     
  • Balakrishna

    Balakrishna - 2015-08-26

    Hi Jamie,
    are you able to confirm, if there is a package that comes with by default SSL2,SSL3 & TLS v1 disabled so we can install?
    Any config changes required?

     
  • Jamie Cameron

    Jamie Cameron - 2015-08-26

    The latest Webmin release allows these old SSL versions to be disabled.

     
    • Balakrishna

      Balakrishna - 2015-08-26

      it is it by default? of need to disable with additional config?
      whats the config required?
      the earlier recommendation by you didn't have option to disable TLS v1

       
      • Balakrishna

        Balakrishna - 2015-08-26

        Whats the version of webmin that allow disabling TLSv1?

         
  • Jamie Cameron

    Jamie Cameron - 2015-08-26

    The current release (1.760) allows disabling of TLS v1. The next release (1.770) will disable it by default at install time.

     
  • Balakrishna

    Balakrishna - 2017-02-10

    Hi Jamie,
    can you confirm if by default, the latest webmin version disable TLS1.0 and TLS1.1 and only enable TLS1.2?

     
  • Jamie Cameron

    Jamie Cameron - 2017-02-10

    The current release disables TLS 1.0, 1.1 and SSL v2 and v3 by default for new installs.

     
    • Balakrishna

      Balakrishna - 2017-02-11

      Hi Jamie,

      For existing installations, how do we force use TLS1.2?

      From: Jamie Cameron [mailto:jcameron@users.sf.net]
      Sent: Saturday, 11 February 2017 7:37 AM
      To: [webadmin:bugs] 4590@bugs.webadmin.p.re.sf.net
      Subject: [webadmin:bugs] #4590 TLS renegotiation vulnerability webmin

      The current release disables TLS 1.0, 1.1 and SSL v2 and v3 by default for new installs.


      [bugs:#4590]https://sourceforge.net/p/webadmin/bugs/4590/ TLS renegotiation vulnerability webmin

      Status: open
      Group: 1.740
      Created: Mon Apr 27, 2015 07:30 AM UTC by Balakrishna
      Last Updated: Fri Feb 10, 2017 08:46 AM UTC
      Owner: nobody

      Hi,

      Due to recent ssl and tls renegotiation vulnerabilities we were able to address ssl with ssl3 disable but how to fix tls renegotiated as this is the only left supported ssl now


      Sent from sourceforge.net because you indicated interest in https://sourceforge.net/p/webadmin/bugs/4590/

      To unsubscribe from further messages, please visit https://sourceforge.net/auth/subscriptions/

      Disclaimer

      This email (and any attachments) are intended solely for the named addressee(s) only. It contains confidential and/or privileged information. If you are not the intended recipient or have received this email in error, you must not copy, distribute, disclose or take any action in reliance on any part of it. In such case, you should inform us immediately and delete this email (and any attachments).

       
  • Jamie Cameron

    Jamie Cameron - 2017-02-11

    You can control allowed protocols and ciphers at Webmin -> Webmin Configuration -> SSL Encryption.

     

Log in to post a comment.