Skip to main content

OpenSSH J-PAKE Session Key Retrieval Vulnerability

Comments

16 comments

  • Infopro
    The docs may be of some use: PCI Compliance Scanning and Software Versions - cPanel Documentation
    0
  • DamienWebb
    Following this guide helped me upgrade to OpenSSH 6.2 from 5.3(default) ptudor.net/linux/openssh/
    0
  • quizknows
    Regarding that 2010 openssh CVE, it is a flase positive and does not affect centos6.
    0
  • inetbizo
    The docs may be of some use:
    0
  • Infopro
    0
  • inetbizo
    0
  • cPanelMichael
    It is missing cipher suite settings for Pure/Pro FTP, Webdisk. How soon can that page be modified?

    Are there specific settings you would like added to the documentation, or are you seeking general input for those services? These threads may help: Thank you.
    0
  • inetbizo
    New data security standards. Add new entries for cipher suites that remove RC4, TLS1.0 See
    0
  • cPanelMichael
    For instance, which specific failures are you receiving in your PCI compliance scan results for FTP and Web Disk when using the default settings? Thank you.
    0
  • inetbizo
    For instance, which specific failures are you receiving in your PCI compliance scan results for FTP and Web Disk when using the default settings? Thank you.

    Michael are you asking me? If so, I can authorize CP to talk w/ Liquidweb, inc. about my PCI ticket and all the changes we've had to make above the defaults. Massive changes at that.
    0
  • cPanelMichael
    I don't believe the updating the document is a good idea for the FTP and Web Disk services because some of those changes may result connection issues for certain customers. That being said, you are welcome to post specific documentation requests here and we can forward those requests to our documentation team. Thank you.
    0
  • inetbizo
    The documentation is for PCI compliance. You know as well as I that DSS recently changed their requirements such as removing RC4 ciphers. The only one that may have issue is TLS v1.0 You can at least annotate the June 30, 2016 deadline and the suggested settings.
    0
  • cPanelMichael
    For instance, could you post the PCI compliance scan results for the FTP and Web Disk services that were failures? Also, which specific changes did you make to address the issue for those services that you would like documented? Thank you.
    0
  • inetbizo
    For instance, could you post the PCI compliance scan results for the FTP and Web Disk services that were failures? Also, which specific changes did you make to address the issue for those services that you would like documented? Thank you.

    I've asked Liquidweb, inc. to respond to this thread to assist with the answer to all CP ports we had to change the cipher, x-frame options, etc.
    0
  • inetbizo
    For instance, could you post the PCI compliance scan results for the FTP and Web Disk services that were failures? Also, which specific changes did you make to address the issue for those services that you would like documented? Thank you.

    Current Apache Pre-Virtual-Host SSLProtocol all -SSLv2 -SSLv3 -TLSv1 SSLHonorCipherOrder On SSLCipherSuite ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!CAMELLIA:!DES:!MD5:!PSK:!RC4
    Current FTP TLS Cipher Configuration HIGH:!aNULL:!eNULL:!PSK:!RC4:!MD5:!TLSv1:!SSLv2:!SSLv3
    Current Webdisk Cipher COnfiguration ECDHE-RSA-AES128-SHA256:AES128-GCM-SHA256:!RC4:HIGH:!MD5:!aNULL:!EDH
    Current Mail Server Cipher Configuration ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:!RC4+RSA:+HIGH:+MEDIUM:!SSLv2
    0
  • cPanelMichael
    The following document has been updated as of 10-13-2015: PCI Compliance and Software Versions - cPanel Knowledge Base - cPanel Documentation Thank you.
    0

Please sign in to leave a comment.