On 10/15/2014 08:16 AM, Jan Tomasek wrote:
Hello,

is http://poodlebleed.com/ related to 389? I think it is, this is not implementation flaw in OpenSSL, this seems to be related to the SSLv3 design.

I've found:
http://directory.fedoraproject.org/docs/389ds/design/nss-cipher-design.html

but new syntax with -SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA doesn't seem to be working on my system:

The new syntax might not yet be supported on 1.2.11 (el5)

https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/9.0/html/Administration_Guide/Managing_SSL-Setting_Security_Preferences.html


ldap-dev:~# yum list installed |grep 389
389-admin.x86_64                      1.1.29-1.el5
389-admin-console.noarch              1.1.8-1.el5
389-admin-console-doc.noarch          1.1.8-1.el5
389-adminutil.x86_64                  1.1.20-1.el5
389-console.noarch                    1.1.7-3.el5
389-ds.noarch                         1.2.1-1.el5
389-ds-base.x86_64                    1.2.11.28-1.el5
389-ds-base-devel.x86_64              1.2.11.28-1.el5
389-ds-base-libs.x86_64               1.2.11.28-1.el5
389-ds-console.noarch                 1.2.6-1.el5
389-ds-console-doc.noarch             1.2.6-1.el5
389-dsgw.x86_64                       1.1.11-1.el5

I'm running on CentOS 5 with EPEL sources.

Thanks

--
389 users mailing list
389-users@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/389-users

Reply via email to