Domanda

I found out my server has SSL v2 enabled. Which is bad. I can't do anything about this as I am on shared hosting (albeit with dedicated IP address).

But when I connect with my browser (chrome and IE11) I see it uses TLS. So my question is, is SSLv2 only used when a really old browser is connecting to the server? Am I right in assuming if someone is connecting with any reasonably in date browser, TLS is likely to be used?

È stato utile?

Soluzione

Yes and no. A recent browser will connect with TLS to the server, but if somebody can arrange a man-in-the-middle attack he can enforce SSLv2. For more information see https://superuser.com/questions/246074/ssl-whats-the-reason-for-disabling-ssl-v2-support

Autorizzato sotto: CC-BY-SA insieme a attribuzione
Non affiliato a StackOverflow
scroll top