Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix OpenSSL error with servers that do unsafe renegotiation #19

Merged
merged 1 commit into from
Jun 11, 2022

Commits on Jun 11, 2022

  1. Allow insecure renegotiation and fix resulting OpenSSL error

    Allow servers that do not support the Renegotiation Indication Extension
    (RFC 5746) and are vulnerable to man-in-the-middle attacks (CVE-2009-3555).
    
    Since we merely run tests, risks remain limited.
    
    (DRL fixed error if TLS version is unspecified, and added '@SECLEVEL=0')
    DimitriPapadopoulos authored and dlenski committed Jun 11, 2022
    Configuration menu
    Copy the full SHA
    445d619 View commit details
    Browse the repository at this point in the history