On 08/08/2014 03:27 PM, Dr. Stephen Henson wrote:
> Disabling them with the cipherlist will still leave you vulnerable. One of the
> bugs this fixed was that an SRP ciphersuites could be specified even if it was
> not present in ClientHello.
>
> If you disable SRP at compile time with no-srp you're OK though.
Thank you very much for your swift response, Steve.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [email protected]
Automated List Manager [email protected]