Re: Expected results for testing Poodlebug using OpenSSL CLI

2014-10-30 Thread Jakob Bohm
On 29/10/2014 21:14, Paul Konen wrote: Hi, I found on the web a way to use your tool to test for the new vulnerability called Poodlebug. The command is: opsnssl s_client –connect ip:port –ssl3 I feel that I have tomcat configured to use TLS only and this is the response back. When I execu

Re: Expected results for testing Poodlebug using OpenSSL CLI

2014-10-30 Thread Florian Weimer
* Paul Konen: > Is the above window showing that is was NOT able to make a SSLv3 connection? Yes, the output is certainly confusing, but it indicates an aborted SSL 3.0 handshake. __ OpenSSL Project

Expected results for testing Poodlebug using OpenSSL CLI

2014-10-29 Thread Paul Konen
Hi, I found on the web a way to use your tool to test for the new vulnerability called Poodlebug. The command is: opsnssl s_client -connect ip:port -ssl3 I feel that I have tomcat configured to use TLS only and this is the response back. [cid:image001.png@01CFF38B.07A521A0] When I execute this