6 ms·
Ok, can you tell in short, which server software is involved? Nginx is not the only one, I guess. At least ssh should also be in the boat ... and the mail serv
by PythonicAlpha 11y ago
Ok, can you tell in short, which server software is involved?
Nginx is not the only one, I guess. At least ssh should also be in the boat ... and the mail server .... and ....
- pfg 11y agoOpenSSH is a different project that doesn't use OpenSSL, so that's not affected. As for other software, it depends on the defaults and how their code disables SSLv2 (i.e. whether they just disable all SSLv2 ciphers, or disable the actual protocol with SSL_OP_NO_SSLv2). Anyway, it's likely that most distributions will backport the fix soon for all supported OS versions (either by disabling SSLv2 too or by including the fix from OpenSSL 1.0.2f that allows SSLv2 handshakes even if SSLv2 ciphers are disabled).