3 ms·
If you want to check your servers for various other attacks with a shell script: https://testssl.sh/ https://testssl.sh/ Also, I'm not seeing any guides on fi
by jqueryin 11y ago
If you want to check your servers for various other attacks with a shell script:
https://testssl.sh/ https://testssl.sh/
Also, I'm not seeing any guides on fixes for Dovecot yet. If you built from source or the defaults aren't working, you can use the following:
ssl_cipher_list = ALL:!LOW:!SSLv2:!EXP:!aNULL
Something more secure (blocks other vulnerabilities):
ssl_cipher_list = ALL:!ADH:!LOW:!SSLv2:!SSLv3:!EXP:!aNULL:!RC4:+HIGH:+MEDIUM
The second one also covers SSlv3. You can read more on why to disable this at: http://disablessl3.com/ http://disablessl3.com/
Also, you may need to update your Exim configs as well:
tls_require_ciphers = AES128+EECDH:AES128+EDH
openssl_options = +no_sslv2 +no_sslv3
If there's anything else I'm missing, let me know.
- pfg 11y agossl_cipher_list = ALL:!LOW:!SSLv2:!EXP:!aNULL Does this just disable all SSLv2 ciphers, or disable SSLv2 via SSL_OP_NO_SSLv2? The former might not be enough, unless your OpenSSL version includes fixes from 1.0.2f and g.
- capnrefsmmat 11y agoDovecot also supports disabling SSLv2 directly: ssl_protocols = !SSLv2 !SSLv3
- yuhong 11y agoPlease don't put !SSLv3 in the cipher list. I had to help out Pinboard who did this: https://twitter.com/yuhong2/status/602545883775836161 https://twitter.com/yuhong2/status/602545883775836161