Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

Already on GitHub? Sign in to your account

SSL 3.0 Should Be Disabled; TLS 1.0 Should Be Minimum Version #612

Closed
harding opened this Issue Oct 20, 2014 · 2 comments

Comments

Projects
None yet
2 participants
Contributor

harding commented Oct 20, 2014

According to Netcraft, Bitcoin.org allows SSL 3.0 connections but these connections are vulnerable to the recently-disclosed POODLE MITM attack.

I recommend setting the server's minimum protocol to TLS 1.0 as outlined in the above article. I think this is the documentation for the correct config setting.

Contributor

saivann commented Oct 20, 2014

@harding Fixed, thanks!

@saivann saivann closed this Oct 20, 2014

Contributor

harding commented Oct 20, 2014

@saivann thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment