FreeBSD Security Advisory FreeBSD-SA-09:15.ssl

Bogdan Ćulibrk bc at default.rs
Thu Dec 10 12:23:04 UTC 2009


Dag-Erling Smørgrav wrote:
> Bogdan Ćulibrk <bc at default.rs> writes:
>> This advisory kinda made big problem here in local (things stopped
>> working). I had to do rollback this update because of "session
>> renegotiation" breakage.
> 
> That's the whole point, the patch disables session renegotiation because
> it's fundamentally broken.
> 
>> Is there some workaround to make things work along with this advisory?
> 
> You didn't mention *what* stopped working.
> 
>> Maybe switch to ports/security/openssl ?
> 
> Won't make any difference.
> 
> DES

Hello,

basically whole communication between two application relied on using
exactly this "funcionality" in openssl.



More information about the freebsd-security mailing list