On Jan 16, 2006, at 7:11, Javier Fernandez-Sanguino wrote:



BTW, rereading the OpenSSL bug report [1] I've found that the following workaround works in order to have the Nessus Client connect to the server. Just add this line to /etc/nessus/nessusd.conf:

ssl_cipher_list = SSLv2:-LOW:-EXPORT:RC4+RSA

I'm going to add this to the default nessusd.conf until bug #338006 is fixed. Does anyone see a problem with the above setting?

You're breaking compatibility with clients not running on Debian (which use TLSv1) and you're using a protocol vulnerable to a man in the middle attack.

Please don't temper with the default values in nessusd.conf. They're set to good values, don't change them.


                                -- Renaud


_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to