Conversation

Replying to
There's this note for CVE-2021-3449: > A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). Disabling client-initiated renegotiation is a standard security measure checked by internet.nl for web/mail servers.
2
5
Replying to and
Client-initiated renegotiation is disabled by default in nginx since November 2009. It should be disabled elsewhere too and should really be disabled by default in a future major version OpenSSL. It's unnecessary attack surface and has been known to be for a very long time.
3
7