issue with SSL reporting vulnerability
Hello,
I have a VPS with two ips using Let's Encrypt plugin to secure our sites. Using the Qualys SSL Labs test, if I scan any site on the primary IP (shared), I am capped at a B grade since the server does not support Forward Secrecy and the site only works in browsers with SNI support. Here's where it gets interesting...
If I can scan the one site on the secondary (dedicated) IP, I get a rating of F, this server is vulnerable to DROWN attack. Under the DROWN report on SSL Labs, it says:
IP Address Port Export Special Status
x.x.x.x 443 Yes Yes Vulnerable (same hostname with SSL v2)
I don't control the IP listed above. If I do a reverse lookup on this IP, it is a different host name but is the actual IP of the company's office, which is different than the IP of their website.
Ignore the F rating or a way to fix it? This is a VPS running latest version of CentOS 6 with latest centos6 open ssl package.
Thanks.
Please sign in to leave a comment.
Comments
0 comments