WebApp Sec mailing list archives

SSL version selection query


From: "Abhishek Kumar" <abhishek.kumar () paladion net>
Date: Tue, 23 Mar 2004 19:00:45 +0530

Hello,

I have a query regarding SSL. There is a web server on which both SSLv2
and SSLv3 are enabled. Along with this all the Cipher suites (including
low strength) are also enabled on this server.

A client is using a browser which supports both SSLv2 and SSLv3, with
high strength encryption. 

My question is:

What version of SSL and Cipher suite will be chosen by default? Will it
always be SSLv3 with maximum strength encryption ? Or is there a
situation where SSLv2 can also be selected with some low strength Cipher
suite.

Thanks

-Abhishek



Current thread: