[openssl-dev] [openssl.org #3977] bug report : Ubutu 12.0.4 : Openssl 1.0.1p : allowing connections with EXP cipher

Kurt Roeckx via RT rt at openssl.org
Mon Aug 3 14:20:37 UTC 2015


On Mon, Aug 03, 2015 at 12:03:26PM +0000, sandeep umesh via RT wrote:
> I was expecting that openssl will reject connection request with EXP cipher
> which is not happening as seen above.
> Could you please verify this? Thanks

If you configure it to allow export ciphers or ALL, of course it's
going to allow them.  The export ciphers have been removed from
DEFAULT.


Kurt




More information about the openssl-dev mailing list