How's my SSL?
howsmyssl.com
howsmyssl.com
I'm surprised to find that Apple's OSX Server (Mavericks) ships without TLS 1.1 or 1.2 support.
Are these not widely deployed? Or no sense of urgency since 1.0 isn't broken.
Interestingly Wkikipedia says that TLS 1.1 and 1.2 only have about 25% adoption on servers. Which is shocking if in fact TLS 1.0 is truly broken.
On the other hand, it wouldn't be too hard to build and install a version of the SSL module compatible with the system Apache linked against a newer OpenSSL version, however, and I wouldn't expect this to break Apple's services, at least not until you install an update that either breaks binary module compatability or clobbers your tweaked module configuration.
I don't use Homebrew, so I couldn't tell you if it's capable of building modules for the system Apache, but building the SSL module "by hand" for system Apache with Homebrew OpenSSL should be straightforward enough.
If I was inclined to download and compile libraries then I'd clearly be better off running a linux distro for complete control.
And, if you're curious about client-side SSL support in general, every server test page simulates about 20 most popular (or important) clients. Scroll down to the "Handshake Simulation" section. If you click on client name you get the full-page client report. https://www.ssllabs.com/ssltest/analyze.html?d=www.ssllabs.c...
If you absolutely require this website to tell you you're safe so you get a warm fuzzy feeling and can sleep at night, update to Firefox Beta. Don't just randomly go and change the settings, then wonder 2 weeks later why your banking website no longer works.
Also note that the site marks Firefox as Bad with TLS 1.0 because it can't verify for sure whether you have BEAST mitigation. But Firefox has BEAST mitigation.
(I mean the site. Not so crazy that FF 26 under OSX 10.9.1 is listed as BAD, but I understand and accept the reasoning.)
Hopefully this will spur the various vendors to abandon old, broken protocols and ciphers.
security.tls.version.max = 3
security.ssl3.rsa_fips_des_ede3_sha = falseI'm not proposing that this is a risk or that Firefox behaves this way---I have no idea. Does anyone else know?
Firefox developers have had to reset these settings in the past in order to save users from self-inflicted insecurity.
Without an explicit effort by Firefox developers to reset these prefs, the prefs won't automatically reset to make sense in the future if the value space of the prefs grows. There is no guarantee of what explicit effort might be taken to deal with non-default values of these prefs in the future.
In my opinion, anyone who wants https://www.howsmyssl.com/ to tell them they are probably okay today should install Firefox Beta (or Aurora or Nightly) instead of manually changing these settings.
(Disclosure: I'm a Gecko developer but I don't work on TLS. Disclaimer: The above is my personal understanding and opinion, not any sort of official statement.)
For whatever it's worth though, while I'm not sure how they're doing their version numbers and it may be quite awhile until this is relevant, you could probably just set the integer really high (like 99 or something) and that would effectively translate into "try the highest version you've got" which might break things sometimes, but it wouldn't leave you stuck in a lower version later at least.
Rather surprised it was dumping down TLS 1.0!
Update: https://www.microsoft.com also breaks.
Edit: It's not an SNI issue, IE 8 on XP can load the site.
Reminded me of an old favorite "Shields Up" https://www.grc.com/shieldsup - Great way to quickly test your Router
I think you mean "firewall" or maybe "NAT box".
Yes, the device on my shelf at home doesn't support BGP, doesn't have any TCAM, and probably falls over with more than 10 routes, and is unlikely to ever have more than the default one. But we call them routers.
The layer 3 switches I work on can do BGP, can do layer 3 routing at hundreds of gigabits per second, but still isn't a router.
Language is flexible, terms aren't strictly used, and I don't think anyone was helped by your "correcting" the grandparent poster.
We badly need to get back to end-to-end or we won't be able to deploy new protocols and apps in a few years. Eg it's doubtful if BitTorrent could take off if it was invented today.
Are you saying that's not a router? I'm pretty sure there are more of those deployed than the big kind.
Like the RFC says, routing is forwarding IP packets unmodified. If you mess with the insides of the packets, you're just a no good packet munging middlebox.
$ curl https://www.howsmyssl.com/a/check | python -mjson.tool
You can check which version of OpenSSL curl is using by doing $ curl -V
http://www.spotht.com/2010/06/how-to-enabledisable-ssl-30-an...
However, the Options in my browser do not include a tab called "Encryption", as the article discusses.
TLS 1.0 in Firefox 26.0 should be secure; it implements 1/n-1 record splitting, so it's safe against BEAST even though this website reports otherwise.
http://security.stackexchange.com/questions/32817/why-dont-m...
But yes, being faced with a huge "Your SSL client is Bad" banner when visiting from up-to-date Firefox is FUD.
0 = SSLv3 1 = TLSv1.0 2 = TLSv1.1 3 = TLSv1.2
For reference: http://kb.mozillazine.org/Security.tls.version.*
Also about:config will let you disable security.ssl3.rsa_fips_des_ede3_sha
Making those changes gives me "Probably Okay" rating on howsmyssl.com
> Bad: Your client is using TLS 1.0, which is very old, possibly susceptible to the BEAST attack, and doesn't have the best cipher suites available either.
Interestingly I get "Probably good" using the Chrome browser on the same phone.
> Google Chrome 32.0.1700.72 (Official Build 243157) m > OS Windows
Anyway I'm getting a nice "Probably Okay" using the latest Firefox Nightly.
I actually never used Opera on the presto engine, and although I miss having more horses in the race, I think Opera based off of chromium is great.