DSA-2141-3 apache2 -- backward compatibility option for SSL/TLS insecureID: oval:org.secpod.oval:def:600564 | Date: (C)2011-09-14 (M)2024-02-19 |
Class: PATCH | Family: unix |
DSA-2141-1 changed the behaviour of the openssl libraries in a server environment to only allow SSL/TLS renegotiation for clients that support the RFC5746 renegotiation extension. This update to apache2 adds the new SSLInsecureRenegotiation configuration option that allows to restore support for insecure clients. More information can be found in the file /usr/share/doc/apache2.2-common/NEWS.Debian.gz .