Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 17 May 2015 15:20:12 -0500
From:      Mark Felder <feld@FreeBSD.org>
To:        freebsd-security@freebsd.org
Subject:   Re: Forums.FreeBSD.org - SSL Issue?
Message-ID:  <1431894012.1947726.271026057.54BB4786@webmail.messagingengine.com>
In-Reply-To: <5556E5DC.7090809@obluda.cz>
References:  <CACRVPYOALi-V8D34zeJTYdSwHshYrqtttqVV3=aP8Yb6ZAxfyg@mail.gmail.com> <2857899F-802E-4086-AD41-DD76FACD44FB@modirum.com> <05636D22-BBC3-4A15-AC44-0F39FB265CDF@patpro.net> <20150514193706.V69409@sola.nimnet.asn.au> <F2460C80-969A-46DF-A44F-6C3D381ABDC3@patpro.net> <5554879D.7060601@obluda.cz> <1431697272.3528812.269632617.29548DB0@webmail.messagingengine.com> <5556E5DC.7090809@obluda.cz>

next in thread | previous in thread | raw e-mail | index | archive | help


On Sat, May 16, 2015, at 01:38, Dan Lukes wrote:
> Mark Felder wrote:
> >> Base OpenSSL in still supported releases is too old version and doesn't
> >> support TLS 1.2 as well.
> >>
> >> Either TLS 1.0 is so insecure and should not be used, or is secure
> >> enough for FreeBSD.
> 
> > When the FreeBSD 8.0 (2009) and 9.0 (2012) releases were cut we didn't
> > have these vulnerabilities or problems.
> 
> All security patches are released because of something discovered after
> release. So it is nothing new nor special.
> 
> But it's not the matter of my comment.
> 
> As far as I know, there has been no discussion on FreeBSD Security
> related to fact that FreeBSD 9 will not receive security patches for
> particular known security issue. Nor even announcement, if it has been
> considered no topic for discussion here.
> 
> So I'm confused (as claimed in previous comment). Other the issue is not
> so severe, then I don't understand why TLS 1.0 needs to be disabled on
> forums. Or it is so severe so I don't understand why there is still no
> Security Advisory dedicated to it. Well, there may be no solution known
> - but even in such case the issue should be announced.
> 
> 

You're not understanding the situation: the vulnerability isn't in
OpenSSL; it's a design flaw / weakness in the protocol. This is why
everyone is running like mad from SSL 3.0 and TLS 1.0.

If you want a fix for your entire OS, upgrade to FreeBSD 10 which has a
newer version of OpenSSL in base that includes TLS 1.1 and 1.2. It's not
ABI compatible with older versions. You can't just wedge it into FreeBSD
8 or 9. Sorry.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1431894012.1947726.271026057.54BB4786>