Univention Bugzilla – Bug 36173
apache: SSL3 protocol attack (3.2)
Last modified: 2015-03-02 09:34:09 CET
We should raise the minimum TLS version used by Apache to 1.0 Browsers which don't even support TLS are incompatible with the UMC and every other web application offered in the App Center. +++ This bug was initially created as a clone of Bug #36172 +++ +++ This bug was initially created as a clone of Bug #36171 +++ +++ This bug was initially created as a clone of Bug #36170 +++ CVE-2014-3566 This will requires fixes in openssl, gnutls and nss. Firefox also needs a fix since it uses a local nss copy. (There are additional Firefox issues, so I'll file a separate bug). http://googleonlinesecurity.blogspot.fr/2014/10/this-poodle-bites-exploiting-ssl-30.html https://www.openssl.org/~bodo/ssl-poodle.pdf
Fixed. Advisory: 2014-10-16-univention-apache.yaml
Tests: OK
OK # SSLv2 no -> wget --secure-protocol=SSLv2 https://10.200.7.150 --no-check-certificate --2014-10-17 09:42:09-- https://10.200.7.150/ Abgebrochen (Speicherabzug geschrieben) (???) # SSLv3 no -> wget --secure-protocol=SSLv3 https://10.200.7.150 --no-check-certificate --2014-10-17 09:42:11-- https://10.200.7.150/ Verbindungsaufbau zu 10.200.7.150:443... verbunden. OpenSSL: error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure Es ist nicht möglich, eine SSL-Verbindung herzustellen. # TLS yes -> wget --secure-protocol=TLSv1 https://10.200.7.150 --no-check-certificate ... 2014-10-17 09:42:14 (29,5 MB/s) - »»index.html.1«« gespeichert [4412/4412] https with firefox/chrome still works (TLS 1) OK - YAML
It should be possible to override the deactivation via UCR.
(In reply to Janek Walkenhorst from comment #4) > It should be possible to override the deactivation via UCR. [apache2/ssl/v2] Description[en]=Enables the insecure protocoll SSL 2.0 (Default: no) Type=bool [apache2/ssl/v3] Description[en]=Enables the insecure protocoll SSL 3.0 (Default: no) Type=bool Advisory: 2014-10-16-univention-apache.yaml
OK
http://errata.univention.de/ucs/3.2/225.html