From a5dcc1d8c6f4a0d38b0ddc84033c1dabf9127fba Mon Sep 17 00:00:00 2001 From: Paul Aurich Date: Fri, 4 Dec 2009 09:48:08 -0800 Subject: Disable SSLv2 by default, it's known to be insecure. --- prosody | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'prosody') diff --git a/prosody b/prosody index 7f69e085..1805e5b2 100755 --- a/prosody +++ b/prosody @@ -177,7 +177,7 @@ function init_global_state() -- Load SSL settings from config, and create a ctx table local global_ssl_ctx = rawget(_G, "ssl") and config.get("*", "core", "ssl"); if global_ssl_ctx then - local default_ssl_ctx = { mode = "server", protocol = "sslv23", capath = "/etc/ssl/certs", verify = "none"; }; + local default_ssl_ctx = { mode = "server", protocol = "sslv23", capath = "/etc/ssl/certs", verify = "none", options = "no_sslv2"; }; setmetatable(global_ssl_ctx, { __index = default_ssl_ctx }); end -- cgit v1.2.3