LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > PCI compliance - disable SSLv2

Reply
 
Thread Tools Display Modes
  #1  
Old 02-19-2013, 01:41 PM
bangsters bangsters is offline
Member
 
Join Date: Dec 2011
Posts: 40
Default PCI compliance - disable SSLv2

Hi. Our interworx box runs on cloudlinux and litespeed. We need to disable SSLv2 for PCI complaince.

How can we accomplish this? Is this on litespeed side where we need to disable?

Please advice.

Thanks
Reply With Quote
  #2  
Old 02-19-2013, 02:12 PM
bangsters bangsters is offline
Member
 
Join Date: Dec 2011
Posts: 40
We edited the ssl.conf files and changed some settings. If we try to do a test, this is what we get:


[root@server ~]# openssl s_client -ssl2 -connect 1xx.xxx.121.xxx:443
CONNECTED(00000003)
140621945898824:error:1407F0E5:SSL routines:SSL2_WRITE:ssl handshake failure:s2_pkt.c:430:
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 422 bytes and written 45 bytes
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : SSLv2
Cipher : 0000
Session-ID:
Session-ID-ctx:
Master-Key:
Key-Arg : None
Krb5 Principal: None
PSK identity: None
PSK identity hint: None
Start Time: 1361311678
Timeout : 300 (sec)
Verify return code: 0 (ok)
---
[root@node1 ~]#


Doesn't this mean that SSLv2 is being rejected? If so, then the server should have passed PCI scanning regarding the SSLv2.

Any idea? Am I missing a step?
Reply With Quote
  #3  
Old 02-19-2013, 02:48 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,339
Quote:
Originally Posted by bangsters View Post
...
CONNECTED(00000003)
140621945898824:error:1407F0E5:SSL routines:SSL2_WRITE:ssl handshake failure:s2_pkt.c:430:
...
This indicates SSL2 is disabled.
Reply With Quote
  #4  
Old 02-19-2013, 02:50 PM
bangsters bangsters is offline
Member
 
Join Date: Dec 2011
Posts: 40
Quote:
Originally Posted by webizen View Post
This indicates SSL2 is disabled.
Yes that's what I thought so too. But then the pci report came out with 3 failures, all related to SSLv2.....

I'm having it run again.

Thank webizen for all your help
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 09:36 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.