Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TLS_FALLBACK_SCSV Support #96

Open
GoogleCodeExporter opened this issue Mar 16, 2015 · 3 comments
Open

TLS_FALLBACK_SCSV Support #96

GoogleCodeExporter opened this issue Mar 16, 2015 · 3 comments

Comments

@GoogleCodeExporter
Copy link

Ubuntu has rolled out TLS_FALLBACK_SCSV patches (TLS Protocol Downgrade attack 
prevention) to their openssl packages, but servers running mod_spdy are still 
affected due to the built-in openssl.

Because of that it would be great if mod_spdy could be updated to include those 
patches.

Original issue reported on code.google.com by [email protected] on 17 Oct 2014 at 4:38

@GoogleCodeExporter
Copy link
Author


Hello,

SPDY does not support TLS_FALLBACK_SCSV in order to prevent
protocol downgrade attacks.

I would like to know if there is an ETA for this feature,
Otherwise I will have to remove SPDY of all our servers.

Thanks in advanced for your expected cooperation and assistance about this 
matter.

Original comment by [email protected] on 11 Feb 2015 at 3:20

@GoogleCodeExporter
Copy link
Author

You can also disable SSL3, unless you still need to support IE6 clients.

Original comment by [email protected] on 19 Feb 2015 at 1:48

@GoogleCodeExporter
Copy link
Author

Thanks it was done

Original comment by [email protected] on 21 Feb 2015 at 11:54

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant