WebApp Sec mailing list archives

RE: SSL version selection query


From: Bénoni MARTIN <Benoni.MARTIN () libertis ga>
Date: Tue, 23 Mar 2004 18:50:26 +0100

Well that depends on what kind of client and server you are using! Usually, there is a list of algorithms on both sides 
(client and server), list that can be set up by the user/administrator. During phase 1 of the Handshake, client sends a 
list to the server, ordering his wishes. Then, the server looks at his own list, and sends back a reply ASAP a match 
has been found...so depends on the configuration of the both sides!:)


-----Message d'origine-----
De : Abhishek Kumar [mailto:abhishek.kumar () paladion net] 
Envoyé : mardi 23 mars 2004 14:31
À : webappsec () securityfocus com
Objet : SSL version selection query

Hello,

I have a query regarding SSL. There is a web server on which both SSLv2
and SSLv3 are enabled. Along with this all the Cipher suites (including
low strength) are also enabled on this server.

A client is using a browser which supports both SSLv2 and SSLv3, with
high strength encryption. 

My question is:

What version of SSL and Cipher suite will be chosen by default? Will it
always be SSLv3 with maximum strength encryption ? Or is there a
situation where SSLv2 can also be selected with some low strength Cipher
suite.

Thanks

-Abhishek





Current thread: