bolden

Member

Last active 7 years ago

  1. 8 years ago
    Mon May 2 21:29:07 2016
    bolden posted in SSL Config for FOP2.

    I understand, but FOP2 is offering up weak ciphers and SSLv2 or SSLv3. How can I disable SSLv2 and v3? How how do I enforce strong ciphers? If all modern browsers support TLS v1.2, we should be able to disable SSLv2/3.

  2. Mon May 2 17:03:02 2016
    bolden started the conversation SSL Config for FOP2.

    When I run Vulnerability scans against our FOP2 server I am seeing warnings for various SSL vulnerabilities on port 4445. These include Weak SSL Ciphers, SSLv2 And SSLv3 detected, and POODLE vulnerability. I know that fop2_server is attached to port 4445. Can anyone give me insight into how to secure the SSL implementation for FOP2?

  3. Wed Apr 27 14:17:47 2016
    bolden joined the forum.