Community Forums
Connect with us on LinkedIn
  
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Mar 2008
    Posts
    9

    Default Ssl 3.0

    I'm trying to setup an SSL certificate on one of my servers, but can't because of the following error.

    Synopsis : The remote service encrypts traffic using a protocol with known weaknesses. Description : The remote service accepts connections encrypted using SSL 2.0, which reportedly suffers from several cryptographic flaws and has been deprecated for several years. An attacker may be able to exploit these issues to conduct man-in-the-middle attacks or decrypt communications between the affected service and clients. See also : http://www.schneier.com/paper-ssl.pdf Solution: Consult the application's documentation to disable SSL 2.0 and use SSL 3.0 or TLS 1.0 instead. See http://support.microsoft.com/kb/216482 for instructions on IIS. See http://httpd.apache.org/docs/2.0/mod/mod _ssl.html for Apache. Risk Factor: Medium / CVSS Base Score : 2 (AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:N) [More]
    How can I go about changing things over to SSL 3.0? It's a Cpanel/WHM server...what are your thoughts?

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by JacobHaug View Post
    I'm trying to setup an SSL certificate on one of my servers, but can't because of the following error.



    How can I go about changing things over to SSL 3.0? It's a Cpanel/WHM server...what are your thoughts?
    What it is essentially complaining about is the SSLCipherSuite permitting SSL 2.0 connections. If you are running cPanel/WHM 11.24 or later, it's easy to change this. Just go to WHM -> Service Configuration -> Apache Configuration -> Global Configuration and edit the SSLCipherSuite as desired, then click "Save" at the bottom of the page.

  3. #3
    Member
    Join Date
    Mar 2008
    Posts
    9

    Default

    Mine is set to the follow....what should I change?

    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:+SSLv2:-EXP

    Would this work?

    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:+SSLv3:-EXP

    What to do, oh what to do...

  4. #4
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by JacobHaug View Post
    Mine is set to the follow....what should I change?

    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:+SSLv2:-EXP

    Would this work?

    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:+SSLv3:-EXP

    What to do, oh what to do...
    The default in 11.24 is as follows, and you may wish to use it:

    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP

Similar Threads & Tags
Similar threads

  1. Filed with Developers [Case 48781] cPanel => TLS/SSL Manager => Create Self-Signed SSL limited St
    By inetbizo in forum Feature Requests for cPanel/WHM
    Replies: 1
    Last Post: 05-18-2011, 12:58 PM
  2. cPanel account SSL not taking over WHM installed SSL
    By carock in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-08-2008, 01:36 PM
  3. ssl not working . Going port 2086 work but not 2087(ssl)
    By gundamz in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-09-2007, 08:26 AM
  4. SSL problem on Firefox - 'incorrect ssl certificate' dialog box pops up
    By waleron in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 02-26-2007, 08:04 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube