Quantcast
Channel: Ignite Realtime : Discussion List - All Communities
Viewing all articles
Browse latest Browse all 10742

SSL 3.0 fallback vulnerability encounters to openfire/bouncycastle?

$
0
0

What's the fuss all about? Read here.

 

So port 5222 is plain / TLS. Port 5223 is SSL - but openfire doesn't use OpenSSL. It uses bouncycastle :-)

 

According to xmpp.net server test my server jabber-server.de uses/allows the following protocols:

 

StartTLS  REQUIRED

 

SSLv2No
SSLv3Yes
TLSv1Yes
TLSv1.1Yes
TLSv1.2Yes
Is bouncycastle/openfire affected by this vulnerability? I rode some xmpp server blogs saying they turned off compression for connections because this could enforce this bug.

 

 

 

 


Viewing all articles
Browse latest Browse all 10742

Trending Articles