3 ms·
Can someone translate this for us dummies. Am I at risk of the DoS attack if I have TLSv1.2 enabled in Nginx?
by polack 6y ago
Can someone translate this for us dummies. Am I at risk of the DoS attack if I have TLSv1.2 enabled in Nginx?
- inbx0 6y agoAfaik Nginx doesn't do TLS renegotiation so I think you're safe. Disclaimer: I know nothing.
- petecooper 6y agoThis was my understanding, too. I checked: http://nginx.org/en/CHANGES http://nginx.org/en/CHANGES >Changes with nginx 1.13.0 >Change: SSL renegotiation is now allowed on backend connections.
- juddgaddie 6y agohttps://stackoverflow.com/a/20001598/843116 https://stackoverflow.com/a/20001598/843116 Looks like it since 0.7.64 or 0.8.23.
- formerly_proven 6y agoThe backend has easier ways to DoS though. Like rejecting connections.
- mwaitjmp 6y agoDoes anyone know about apache?
- throwaway823882 6y agoIt depends on the version of apache and openssl. Check the version of openssl that your apache binary is dependent on. All versions of 1.1.1 before 1.1.1k are vulnerable. ubuntu:~$ dpkg -s apache2-bin | grep ^Depends | sed -e 's/, /\n/g' | grep libssl | awk '{print $1}' | xargs dpkg -s | grep ^Version Version: 1.1.1j-1+ubuntu18.04.1+deb.sury.org+3 First try to just upgrade openssl on your system. Check the package's changelog (ex: http://changelogs.ubuntu.com/changelogs/pool/main/o/openssl/openssl_1.1.1f-1ubuntu4.2/changelog http://changelogs.ubuntu.com/changelogs/pool/main/o/openssl/...) to see if a fix has been backported into it, the version number may not indicate it. If you can't tell, try to install an older 1.0.x version. Then restart apache. (The magic of dynamic libraries... it'll be fun when Go's ssl library has a bug) If that doesn't work, try configuring SSLOptions -OptRenegotiate and then point ssllabs at it to see if reneg is disabled. If that doesn't work, recompile apache against a not-vulnerable version of openssl. Maybe the easiest way to do that is take the Dockerfile (https://github.com/docker-library/httpd/blob/master/2.4/Dockerfile https://github.com/docker-library/httpd/blob/master/2.4/Dock...), take out libssl-dev, compile a specific openssl version, then link against it.