SSL 3.0 - Poodle Vulnerability

Got an idea? Missing something? Post your feature request here.

Moderator: moderators

SSL 3.0 - Poodle Vulnerability

Postby jgalloway84 » Tue Oct 21, 2014 6:03 pm

I was curious if there is a way to disable SSL 3.0 with Subsonic due to Poodle. I have Subsonic running on it a mac and edited /Applications/Subsonic.app/Contents/Info.plist to enable https on an alternate port (4000 for my example). Everything works, but I can connect to Subsonic with SSL3.0 and I would like to disable it since it's no longer secure.

Testing for SSL 3.0: (yourdomain.com with port 4000) in Linux: openssl s_client -connect yourdomain:4000 -ssl3)

It appears Subsonic is using Jetty for the webserver and I do not see a way to disable SSL 3.0.

Question:
1. Can we disable SSL 3.0? Would it require a new release of Subsonic or is there a config file we can edit?
2. Side note, how would we use signed SSL certificates?

Thanks guys!
jgalloway84
 
Posts: 1
Joined: Tue Oct 21, 2014 5:55 pm

Re: SSL 3.0 - Poodle Vulnerability

Postby daneren2005 » Tue Oct 21, 2014 6:24 pm

Some quick googling shows that it would almost definitely require a server update.
Developer of DSub for Android
daneren2005
 
Posts: 1709
Joined: Fri Jul 06, 2012 7:52 pm

Re: SSL 3.0 - Poodle Vulnerability

Postby drsbaitso » Fri Oct 24, 2014 4:07 pm

jgalloway84 wrote:I was curious if there is a way to disable SSL 3.0 with Subsonic due to Poodle. I have Subsonic running on it a mac and edited /Applications/Subsonic.app/Contents/Info.plist to enable https on an alternate port (4000 for my example). Everything works, but I can connect to Subsonic with SSL3.0 and I would like to disable it since it's no longer secure.

Testing for SSL 3.0: (yourdomain.com with port 4000) in Linux: openssl s_client -connect yourdomain:4000 -ssl3)

It appears Subsonic is using Jetty for the webserver and I do not see a way to disable SSL 3.0.

Question:
1. Can we disable SSL 3.0? Would it require a new release of Subsonic or is there a config file we can edit?
2. Side note, how would we use signed SSL certificates?

Thanks guys!


Why not just use a reverse proxy or something? Mine goes through Apache so I can handle everything without messing with subsonic.
drsbaitso
 
Posts: 6
Joined: Wed Nov 23, 2011 3:34 pm


Return to Feature Requests

Who is online

Users browsing this forum: No registered users and 9 guests