On Jan 16, 2006, at 7:11, Javier Fernandez-Sanguino wrote:
BTW, rereading the OpenSSL bug report [1] I've found that the
following workaround works in order to have the Nessus Client
connect to the server. Just add this line to /etc/nessus/nessusd.conf:
ssl_cipher_list = SSLv2:-LOW:-EXPORT:RC4+RSA
I'm going to add this to the default nessusd.conf until bug #338006
is fixed. Does anyone see a problem with the above setting?
You're breaking compatibility with clients not running on Debian
(which use TLSv1) and you're using a protocol vulnerable to a man in
the middle attack.
Please don't temper with the default values in nessusd.conf. They're
set to good values, don't change them.
-- Renaud
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus