Member
Last active 7 years ago
I understand, but FOP2 is offering up weak ciphers and SSLv2 or SSLv3. How can I disable SSLv2 and v3? How how do I enforce strong ciphers? If all modern browsers support TLS v1.2, we should be able to disable SSLv2/3.
When I run Vulnerability scans against our FOP2 server I am seeing warnings for various SSL vulnerabilities on port 4445. These include Weak SSL Ciphers, SSLv2 And SSLv3 detected, and POODLE vulnerability. I know that fop2_server is attached to port 4445. Can anyone give me insight into how to secure the SSL implementation for FOP2?