[naviserver-devel] I've update to solve SSL/TLS MITM vulnerability

2014-06-20 Thread Cesáreo García Rodicio
Hi! I had an F in Qualys SSL Labs due to the most recent openssl bug (SSL/TLS MITM vulnerability (CVE-2014-0224): https://www.openssl.org/news/secadv_20140605.txt). So, - I've upgrade openssl (in my box via debian apt-get update and apt-get upgrade). Now with OpenSSL 1.0.1e 11 Feb 2013 - I

Re: [naviserver-devel] I've update to solve SSL/TLS MITM vulnerability

2014-06-20 Thread Gustaf Neumann
Dear all, Cesareo, you are right. For CVE-2014-0224, an upgrade of openssl + restart of naviserver is sufficient. There is no need to upgrade naviserver or nsssl. -gustaf neumann Am 20.06.14 23:45, schrieb Cesáreo García Rodicio: > Hi! > > I had an F in Qualys SSL Labs due to the most recent ope