On Fri, 13 Oct 2017 03:17:22 -0700 (PDT),
anee...@gmail.com <
anee...@gmail.com>, in
<
f2c0340f-9239-4aa8...@googlegroups.com> wrote:
> I tried to add the line "SSLProtocol All -SSLv2 -SSLv3 -TLSv1
> +TLSv1.1 +TLSv1.2" in httpd.conf And restarted Apached, it throws
> below error "SSLProtocol: Illegal protocol '"TLSv1.1"'
Shouldn't that be "-all" instead of "all"? If my memory serves, that
means you will accept *all* protocols, then the rest of the stanza
doesn't matter since the rules apply left to right.
> Now iam worried whether to install these dependencies or not. Will
> they affect my running httpd instances ? Is there any other way to
> remediate this vulnerability ?
That will require a restart of your http/s service. Given that this is
a stateless transaction, this shouldn't be a huge issue. Otherwise,
you're running a potentially vulnerable service listening to the
internet.
If you're worried about compatibility with your current configuration,
you may want to run the update against a spare server, or a virtual
machine with the same software and configuration.
--
Consulting Minister for Consultants, DNRC
I can please only one person per day. Today is not your day. Tomorrow
isn't looking good, either.
I am BOFH. Resistance is futile. Your network will be assimilated.