What exactly is a cipher and how can I block weak ones?
Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Yeah I found the logic slightly odd when face with Nessus whining about this, as sure, there's a potential MITM issue when using a weak cipher, but that relies on that cipher being use in the first place, and that's pretty unlikely now. So unless you have a bad browser upgrade policy and what not, you're never actually vulnerable to ssl2 cipher issues anyway. I would say though that the browsers still generally *CAN* use sub 128bit ciphers - if a server only supports md5-des or such then you don't want to be blocked from accessing that server, good way to get a bad reputation as a browser, but they'd never get that low on the list unless the server is in that situation.
Last edited by acid_kewpie; 08-02-2009 at 02:00 PM.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.