On Fri, Aug 08, 2014, Henning Horst wrote: > > can someone please clarify whether or not this vulnerability affects > 1.0.1 clients which explicitly disable SRP ciphers via > SSL_CTX_set_cipher_list? >
Disabling them with the cipherlist will still leave you vulnerable. One of the bugs this fixed was that an SRP ciphersuites could be specified even if it was not present in ClientHello. If you disable SRP at compile time with no-srp you're OK though. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [email protected] Automated List Manager [email protected]
