29 Oct
2014
29 Oct
'14
1:16 a.m.
Hi guys In my project I am using syslog-ng as syslog client and send log via TLS. We all know that recently there is one new security flaw which is Poodle(CVE-2014-3566 - SSLv3 Fallback Vulnerability) This requires disabling SSLv3 I have checked admin guide of syslog-ng 3.3.2 but I am able to find the option Could you please let me know the way? Alternatively I think I may achieve the object by disable SSLv3 ciphers used by syslog-ng client original ciphers used by us is ALL:!SSLv2:!MEDIUM:!LOW:!EXP:!ADH:!ECDH:!PSK:!MD5:@STRENGTH I may change it to ALL:!SSLv3:!SSLv2:!MEDIUM:!LOW:!EXP:!ADH:!ECDH:!PSK:!MD5:@STRENGTH Bug this will make syslog-ng only supports TLS1.2 and cause negative impact to interoperability Thanks Jason