summaryrefslogtreecommitdiff
path: root/src/README.UPDATING
diff options
context:
space:
mode:
authorPhil Pennock <pdp@exim.org>2012-05-06 02:50:57 -0700
committerPhil Pennock <pdp@exim.org>2012-05-06 02:50:57 -0700
commitf0f5a555bee153477d12bcbce90875d46884281c (patch)
tree7d1c217de6f49a7b70c1058afe7eb4680bb39d04 /src/README.UPDATING
parent5bfb4cdf352ad40304c6bbf0d826569dea761699 (diff)
downloadexim4-f0f5a555bee153477d12bcbce90875d46884281c.tar.gz
Disable SSLv2 by default.
Diffstat (limited to 'src/README.UPDATING')
-rw-r--r--src/README.UPDATING11
1 files changed, 9 insertions, 2 deletions
diff --git a/src/README.UPDATING b/src/README.UPDATING
index 5b6bea869..12335eab8 100644
--- a/src/README.UPDATING
+++ b/src/README.UPDATING
@@ -39,6 +39,12 @@ Exim version 4.78
the message. No tool has been provided as we believe this is a rare
occurence.
+ * For OpenSSL, SSLv2 is now disabled by default. (GnuTLS does not support
+ SSLv2). RFC 6176 prohibits SSLv2 and some informal surveys suggest no
+ actual usage. You can re-enable with the "openssl_options" Exim option,
+ in the main configuration section. Note that supporting SSLv2 exposes
+ you to ciphersuite downgrade attacks.
+
* With OpenSSL 1.0.1+, Exim now supports TLS 1.1 and TLS 1.2. If built
against 1.0.1a then you will get a warning message and the
"openssl_options" value will not parse "no_tlsv1_1": the value changes
@@ -48,8 +54,9 @@ Exim version 4.78
"openssl_options" gains "no_tlsv1_1", "no_tlsv1_2" and "no_compression".
COMPATIBILITY WARNING: The default value of "openssl_options" is no longer
- "+dont_insert_empty_fragments". We default to unset. That old default was
- grandfathered in from before openssl_options became a configuration option.
+ "+dont_insert_empty_fragments". We default to "+no_sslv2".
+ That old default was grandfathered in from before openssl_options became a
+ configuration option.
Empty fragments are inserted by default through TLS1.0, to partially defend
against certain attacks; TLS1.1+ change the protocol so that this is not
needed. The DIEF SSL option was required for some old releases of mail