FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
- From: Garrett Wollman <wollman@xxxxxxxxxxxxxx>
- Date: Thu, 3 Dec 2009 17:52:58 -0500
<<On Thu, 3 Dec 2009 09:30:39 GMT, FreeBSD Security Advisories <security-advisories@xxxxxxxxxxx> said:
NOTE WELL: This update causes OpenSSL to reject any attempt to renegotiate
SSL / TLS session parameters. As a result, connections in which the other
party attempts to renegotiate session parameters will break. In practice,
however, session renegotiation is a rarely-used feature, so disabling this
functionality is unlikely to cause problems for most systems.
Actually, pretty much anyone who uses client certificates in an
enterprise environment is likely to have a problem with this, which is
why the IETF TLS working group is working on publishing a protocol
fix. It looks like that RFC should be published, at Proposed
Standard, in a few weeks, and most vendors look prepared to release
implementations of the fix immediately thereafter (as soon as the
relevant constants are assigned by IANA).
-GAWollman
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- References:
- FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
- Prev by Date: FreeBSD Security Advisory FreeBSD-SA-09:15.ssl [REVISED]
- Next by Date: Re: FreeBSD Security Advisory FreeBSD-SA-09:16.rtld
- Previous by thread: FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
- Next by thread: Re: FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
- Index(es):