<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #797: POODLE: SSLv3.0 vulnerability (CVE-2014-3566)</title>
    <link>http://localhost:8080/trac/ticket/797</link>
    <description>&lt;p&gt;
Check which serives are available with SSLv3.0, see:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://access.redhat.com/articles/1232123"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://access.redhat.com/articles/1232123&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.openssl.org/~bodo/ssl-poodle.pdf"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.openssl.org/~bodo/ssl-poodle.pdf&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3566"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3566&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
and disable SSLv3.0 where it is being offered.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/797</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 15 Oct 2014 13:01:15 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/797#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/797#comment:1</guid>
      <description>
        &lt;p&gt;
A couple more links:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://askubuntu.com/questions/537196/how-do-i-patch-workaround-sslv3-poodle-vulnerability-cve-2014-3566"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://askubuntu.com/questions/537196/how-do-i-patch-workaround-sslv3-poodle-vulnerability-cve-2014-3566&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://googleonlinesecurity.blogspot.de/2014/10/this-poodle-bites-exploiting-ssl-30.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://googleonlinesecurity.blogspot.de/2014/10/this-poodle-bites-exploiting-ssl-30.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 16 Oct 2014 12:42:39 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/797#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/797#comment:2</guid>
      <description>
        &lt;p&gt;
This will be fixed for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt; by &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/798" title="maintenance: BOA-2.3.5 (closed: fixed)"&gt;ticket:798&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 11 Nov 2014 13:27:06 GMT</pubDate>
      <title>hours, status, totalhours changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/797#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/797#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
&lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;PenguinServer&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; were vulnerable:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.ssllabs.com/ssltest/analyze.html?d=parrot.transitionnetwork.org&amp;amp;hideResults=on"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.ssllabs.com/ssltest/analyze.html?d=parrot.transitionnetwork.org&amp;amp;hideResults=on&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.ssllabs.com/ssltest/analyze.html?d=penguin.transitionnetwork.org&amp;amp;hideResults=on"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.ssllabs.com/ssltest/analyze.html?d=penguin.transitionnetwork.org&amp;amp;hideResults=on&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
On &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;PenguinServer&lt;/a&gt;, find the files to edit:
&lt;/p&gt;
&lt;pre class="wiki"&gt;cd /etc/nginx/
grep -rli sslv3 .
./sites-available/stats
./sites-available/tech
./sites-available/static
./sites-available/default
./sites-available/intransitionmovie
./sites-available/penguin
./sites-available/ttarchive
./sites-available/wiki.bak
./sites-available/patterns
./sites-available/wiki
&lt;/pre&gt;&lt;p&gt;
Edit in vim:
&lt;/p&gt;
&lt;pre class="wiki"&gt;:1,$s/ssl_protocols SSLv3 /ssl_protocols /gc
&lt;/pre&gt;&lt;p&gt;
Restart Nginx.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; edit &lt;tt&gt;&lt;/tt&gt;&lt;tt&gt;/etc/apache2/mods-available/ssl.conf&lt;/tt&gt;&lt;tt&gt;&lt;/tt&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;#SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.1 +TLSv1.2
SSLProtocol -ALL +TLSv1 +TLSv1.1 +TLSv1.2
&lt;/pre&gt;&lt;p&gt;
Restart Apache.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>