Re: DoS vulnerability due to client-initiated renegotiation

2011-11-06 Thread Vincent Bernat
OoO En cette fin de nuit blanche du dimanche 06 novembre 2011, vers 06:01, Amol disait : > I would also be interested in knowing about the fix for this I still haven't found a way to patch this. I have asked on OpenSSL mailing list with no luck. I still need to investigate more. > an

Re: DoS vulnerability due to client-initiated renegotiation

2011-11-02 Thread Vincent Bernat
OoO En ce début de soirée du mercredi 02 novembre 2011, vers 21:34, "David Prothero" disait : > I have been looking for a way to disable client-initiated > renegotiation on stunnel/openssl but haven’t found a way. On the > options description here: [...] As far as I know, there is no easy w

DoS vulnerability due to client-initiated renegotiation

2011-11-02 Thread David Prothero
HAProxy version 1.4.18 stunnel 4.44 with X-Forwarded-For patch OpenSSL 0.9.8k 25 Mar 2009 Ubuntu 10.04.3 LTS I'm submitting this here rather than to stunnel's list as I'm not using the most recent version of stunnel due to needing the X-Forwarded-For patch. When I scan my domain (https:/