From owner-freebsd-security@FreeBSD.ORG Thu Oct 13 20:44:32 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5888516A423 for ; Thu, 13 Oct 2005 20:44:32 +0000 (GMT) (envelope-from jacques@vidrine.us) Received: from mail.phi23.org (phi23.org [161.58.133.165]) by mx1.FreeBSD.org (Postfix) with ESMTP id 7BB8243D45 for ; Thu, 13 Oct 2005 20:44:31 +0000 (GMT) (envelope-from jacques@vidrine.us) Received: from [17.202.43.236] (A17-202-43-236.apple.com [17.202.43.236]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (Client did not present a certificate) by mail.phi23.org (Postfix) with ESMTP id 5F99C2509C; Thu, 13 Oct 2005 20:44:30 +0000 (UTC) In-Reply-To: <20051012191019.GJ2482@cirb503493.alcatel.com.au> References: <200510111202.j9BC2obf081876@freefall.freebsd.org> <434BCB75.2000402@iang.org> <20051012191019.GJ2482@cirb503493.alcatel.com.au> Mime-Version: 1.0 (Apple Message framework v746.2) Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Message-Id: <47D785F8-E28E-4753-ABE9-8627107D9038@vidrine.us> Content-Transfer-Encoding: 7bit From: Jacques Vidrine Date: Thu, 13 Oct 2005 13:44:28 -0700 To: Peter Jeremy X-Mailer: Apple Mail (2.746.2) X-Mailman-Approved-At: Fri, 14 Oct 2005 12:44:02 +0000 Cc: freebsd-security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 13 Oct 2005 20:44:32 -0000 On 2005-10-12, at 12:10 :19, Peter Jeremy wrote: > On Tue, 2005-Oct-11 09:45:53 -0700, Jacques Vidrine wrote: >> On Oct 11, 2005, at 7:25 AM, Ian G wrote: >>> Isn't the workaround obviously to switch off V2? >> >> Yes. Sorry that wasn't mentioned. > > That sounds like a good workaround. How do I implement it? I've > looked through the documentation and can't find any reference to a > runtime OpenSSL configuration file that would let me do this. I'm not aware of a global option for OpenSSL, either. Disabling SSLv2 would need to be handled by the application, i.e. turn off SSLv2 for each of your SSL/TLS applications. Cheers, -- Jacques Vidrine