The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

patch "SSL Protocol Version 2 Detection"

Discussion in 'General Discussion' started by jusfeel, Jul 24, 2008.

  1. jusfeel

    jusfeel Registered

    Mar 2, 2008
    Likes Received:
    Trophy Points:

    We need some help to secure our server. I don't know how to patch this via Cpanel. Here is what the vulnerablity description and recommended solution I got. Does anyone know something?
    The remote service appears to encrypt traffic using SSL protocol version 2.

    Netscape Communications Corporation introduced SSL 2.0 with the launch of Netscape Navigator 1.0 in 1994 and it contains several well-known weaknesses. For example, SSLv2 doesn't provide any protection against man-in-the-middle attacks during the handshake, and uses the same cryptographic keys for message authentication and for encryption.

    In Internet Explorer 7, the default HTTPS protocol settings are changed to disable the weaker SSLv2 protocol and to enable the stronger TLSv1 protocol. By default, IE7 users will only negotiate HTTPS connections using SSLv3 or TLSv1. Mozilla Firefox is expected to drop support for SSLv2 in its upcoming versions.

    As almost all modern browsers support SSLv3, disabling support for the weaker SSL method should have minimal impact. The following browsers support SSLv3:
      Internet Explorer 5.5 or higher (PC)
      Internet Explorer 5.0 or higher (Mac)
      Netscape 2.0 (Domestic) or higher (PC/Mac)
      Firefox 0.8 or higher (PC/Mac/Linux)
      Mozilla 1.7 or higher (PC/Mac/Linux)
      Camino 0.8 or higher (Mac)
      Safari 1.0 or higher (Mac)
      Opera 1.7 or higher (PC/Mac)
      Omniweb 3.0 or higher (Mac)
      Konqueror 2.0 or higher (Linux)

    General Solution
    Consult the application's documentation to disable SSL 2.0 and use SSL 3.0 or TLS 1.0 instead. Consult your documentation to identify how to reconfigure the affected application to avoid use of weak ciphers. Some knowledge base articles are listed below.

    Apache Implementation:
    In Apache, you need to modify the SSLCipherSuite directive in the httpd.conf or ssl.conf file. An example would be editing the following lines to something like:
    SSLProtocol -ALL +SSLv3 +TLSv1

    More information can be read by clicking the Apache sslciphersuite directive information link below.


Share This Page