severity 722105 serious
tags 722105 security
thanks

Having SSLv2 enabled is not acceptable for a server in Debian, especially
since it apparently cannot be disabled by user configuration. Please
ensure that >= 2.1.12 enters the archive.

Also, can you investigate whether the relevant changes:
- Disable old and unsecure ciphers in TLS driver
- Disable SSL 2.0 in TLS driver
are suitable for squeeze and wheezy?


thanks,
Thijs


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to