Bug#765702: lighttpd: Disable SSL 3.0

2014-10-17 Thread Christian Tacke
Hi, On Fri, Oct 17, 2014 at 18:47:50 +0200, Stefan Bühler wrote: [...] > I'd say go with this instead: > http://git.lighttpd.net/lighttpd/lighttpd-1.x.git/commit/?id=084df7e99a8738be79f83e330415a8963280dc4a That also works of course. Go with whatever makes maintainers happy. Just please consid

Bug#765702: lighttpd: Disable SSL 3.0

2014-10-17 Thread Stefan Bühler
Hi, On Fri, 17 Oct 2014 14:39:52 +0200 Christian Tacke wrote: > Hi, > > looking at CVE-2014-3566 ("POODLE") it seems a very good > idea to finally disable SSL 3.0 by default ("secure by > default"). Please test attached patch. I'd say go with this instead: http://git.lighttpd.net/lighttpd/ligh

Bug#765702: lighttpd: Disable SSL 3.0

2014-10-17 Thread Christian Tacke
Package: lighttpd Version: 1.4.31-4+deb7u3 Tags: patch Hi, looking at CVE-2014-3566 ("POODLE") it seems a very good idea to finally disable SSL 3.0 by default ("secure by default"). Please test attached patch. Cheers Christian Tacke -- www.cosmokey.com --- ./debian/conf-available/10-ssl.conf~