Disable SSLv3 and RC4
Nux!
nux at li.nux.ro
Wed Sep 14 08:13:45 PDT 2016
Nikos,
I had a look and the self-signed cert shows this:
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
LetsEncrypt shows:
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE
It would appear both should support FS, yet when I use that config line no ciphers can be negotiated.
Lucian
--
Sent from the Delta quadrant using Borg technology!
Nux!
www.nux.ro
----- Original Message -----
> From: "Nikos Mavrogiannopoulos" <n.mavrogiannopoulos at gmail.com>
> To: "Nux!" <nux at li.nux.ro>
> Cc: "openconnect-devel" <openconnect-devel at lists.infradead.org>
> Sent: Tuesday, 13 September, 2016 18:59:18
> Subject: Re: Disable SSLv3 and RC4
> On Tue, 2016-09-13 at 16:03 +0100, Nux! wrote:
>> Nikos,
>>
>> Thanks for that, it will take me a bit to digest it.
>> The cert might be as you suspect since it's a letsencrypt one.
>
> Could you paste the text form of your certificate (not key) as reported
> by certtool or openssl x509?
>
> From certtool you should see something like:
> Key Purpose (not critical):
> TLS WWW Server.
> Key Usage (critical):
> Digital signature.
> Key encipherment.
>
> The Digital signature part of the key usage enables the DHE and ECDHE
> ciphersuites (forward secrecy).
>
> regards,
> Nikos
More information about the openconnect-devel
mailing list