5 ms·
And for testing your servers: https://www.ssllabs.com/ssltest/analyze.html https://www.ssllabs.com/ssltest/analyze.html
by mathrawka 13y ago
And for testing your servers: https://www.ssllabs.com/ssltest/analyze.html https://www.ssllabs.com/ssltest/analyze.html
- josho 13y agoThanks for that. I'm surprised to find that Apple's OSX Server (Mavericks) ships without TLS 1.1 or 1.2 support. Are these not widely deployed? Or no sense of urgency since 1.0 isn't broken.
- outside1234 13y agoApple still ships a server? Didn't know that.
- cvburgess 13y agohttps://www.apple.com/osx/server/ https://www.apple.com/osx/server/
- 72deluxe 13y agoServer software as an add on downloadable from the App Store on the Mac, not a physical server like XServe. They recommend a Mac Mini with two hard disks installed as a SOHO server but obviously aren't catering for large neworks - no hot-swappable drives or fancy RAID for example (unless you use an external Thunderbolt caddy). They're leaving that market to Windows AD and Linux (mostly Windows AD I suspect). Oddly, the server software on the Mac gets less and less features each release since Snow Leopard apparently. I think Ars Technica has a review of the server software, and is pretty in-depth.
- deleted 13y ago[deleted]
- DiabloD3 13y agoIIRC they just ship Apache, so just follow the normal instructions for enabling perfect forward secrecy on Apache.
- wiml 13y agoThey ship Apache, but they only ship obsolescent (0.9.8) versions of OpenSSL. So their system Apache is built against OpenSSL 0.9.8y.
- DiabloD3 13y agoThats rather unfortunate. I think you can use Homebrew to pull in newer stuff, though, but I haven't tried (I don't host stuff on my MBP, I use my Linux workstation for that).
- jasomill 13y agoI'm sure you could, but bear in mind that several OS X Server services are built on top of the system Apache and its configuration file structure, so you probably don't want to replace it with a package manager-built version if you rely on any of these services. On the other hand, it wouldn't be too hard to build and install a version of the SSL module compatible with the system Apache linked against a newer OpenSSL version, however, and I wouldn't expect this to break Apple's services, at least not until you install an update that either breaks binary module compatability or clobbers your tweaked module configuration. I don't use Homebrew, so I couldn't tell you if it's capable of building modules for the system Apache, but building the SSL module "by hand" for system Apache with Homebrew OpenSSL should be straightforward enough.
- josho 13y agoThe point however is that for a few bucks Apple gives me a dead simple GUI to manage a few key services 'that just works'. If I was inclined to download and compile libraries then I'd clearly be better off running a linux distro for complete control.
- tptacek 13y agoTLS 1.0 is definitely broken; TLS 1.1 introduced explicit per-record IVs for CBC mode.
- josho 13y agoHow is TLS 1.0 broken? All I could find is BEAST, but that seems to be mitigated by client patches. Interestingly Wkikipedia says that TLS 1.1 and 1.2 only have about 25% adoption on servers. Which is shocking if in fact TLS 1.0 is truly broken.
- tptacek 13y agoTLS 1.0 uses chained IVs, which is a protocol flaw. It also has an explicit protocol alert for decryption failures, which makes error oracle attacks simpler. TLS 1.0 is broken. It isn't catastrophically broken so far as we know now, but nobody should be deliberately preferring it.
- glazskunrukitis 13y agoThere is also this one - https://getssl.me/en/ssl-checker/news.ycombinator.com https://getssl.me/en/ssl-checker/news.ycombinator.com
- ivanr 13y agoSSL Labs also has a client test: https://www.ssllabs.com/ssltest/viewMyClient.html https://www.ssllabs.com/ssltest/viewMyClient.html And, if you're curious about client-side SSL support in general, every server test page simulates about 20 most popular (or important) clients. Scroll down to the "Handshake Simulation" section. If you click on client name you get the full-page client report. https://www.ssllabs.com/ssltest/analyze.html?d=www.ssllabs.com https://www.ssllabs.com/ssltest/analyze.html?d=www.ssllabs.c...