Portál AbcLinuxu, 22. července 2025 15:03
ouch...
One possibility would be to issue client certificates earlier, before a specific URL is requested.
rozumiem tomu dobre, ze to efektivne zabrani konfiguracii viacerych SSL virtualhostov na jednu IP adresu? tusim ze sa prave kvoli tejto feature TLS rozsirovalo (uz davnejsie), a teraz to zase bude musiet ist k ladu? :)
Changes between 0.9.8k and 0.9.8l [5 Nov 2009] *) Disable renegotiation completely - this fixes a severe security problem (CVE-2009-3555) at the cost of breaking all renegotiation. Renegotiation can be re-enabled by setting SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION in s3->flags at run-time. This is really not recommended unless you know what you're doing. [Ben Laurie]
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.