Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    Jul 2009
    Posts
    27

    Default SSLCipherSuite and security

    Hi,

    I have installed the CSF Firewall. When I do a check it says that :
    Cipher list []. Due to weaknesses in the SSLv2 cipher you should disable SSLv2 in WHM > Apache Configuration > Global Configuration > SSLCipherSuite > Add -SSLv2 to SSLCipherSuite and/or remove +SSLv2. Do not forget to Save AND then Rebuild Configuration and Restart Apache, otherwise the changes will not take effect in httpd.conf
    What I do not understand is that when I go to the link provided to apache global configuration, the SSLCipherSuite line looks like this :
    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP
    And according to what is written below, this is the default.

    So my SSLv2 is already disabled.

    So why CSF continues to say I should disable it?

    Thanks

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    10,720
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by Julien PHAM View Post
    ...

    So why CSF continues to say I should disable it?

    Thanks
    You may want to ask the ConfigServer folks yourself: ConfigServer Services

Similar Threads & Tags
Similar threads

  1. Check Apache weak SSL/TLS Ciphers (SSLCipherSuite)
    By crazyaboutlinux in forum New User Questions
    Replies: 2
    Last Post: 08-19-2009, 04:02 AM
  2. Simple security question about mod-security rule sets.
    By jols in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-09-2007, 05:37 AM
  3. Replies: 109
    Last Post: 06-22-2004, 08:39 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube