[openssl-dev] Logjam clarification

Chris Hill chris.hillsec at gmail.com
Thu May 21 01:41:57 UTC 2015


Folks, can you pls confirm that none of the below ciphers are affected by
this bug? From my understanding, only ciphers containing DH or DHE would be
affected.

TLS_RSA_EXPORT1024_WITH_DES_CBC_SHA (0x62)
TLS_RSA_EXPORT1024_WITH_RC4_56_SHA
TLS_RSA_EXPORT_WITH_RC4_40_MD5
TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5
TLS_RSA_WITH_DES_CBC_SHA

The above are weak, no argument there, but just want to ensure these are
not vulnerable to this newly published bug.

Thanks all!
Chris.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20150520/e4a09615/attachment.html>


More information about the openssl-dev mailing list