Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu May 01, 2014 12:34 pm 
Offline
Senior Newbie

Joined: Thu May 01, 2014 12:25 pm
Posts: 5
It would be great if we could remove the 3DES cipher suites (which have low security characteristics) from the supported cipher suites at the NodeBalancer.


Top
   
PostPosted: Thu May 01, 2014 12:35 pm 
Offline
Senior Newbie

Joined: Sun Dec 08, 2013 8:58 am
Posts: 7
I am happy to see that this is reviewed internally. Can you please provide some more information about why you feel this should be removed? Supporting documentation would be very helpful.


Top
   
PostPosted: Thu May 01, 2014 12:55 pm 
Offline
Senior Member

Joined: Mon Jul 05, 2010 5:13 pm
Posts: 392
We're explicitly limiting the cipher suite to "!RC4:HIGH:!aNULL:!MD5". The resulting ciphers are solid and that choice was made consciously. If you have specific evidence to support 3DES being a harmful cipher, we'll definitely reevaluate that, but a more efficient use of your time might be convincing the powers that be to redefine "HIGH" in accordance with your findings.

- Les


Top
   
PostPosted: Sun May 04, 2014 12:47 am 
Offline
Senior Newbie

Joined: Thu May 01, 2014 12:25 pm
Posts: 5
Actually, that was my mistake. I thought the issue was the 3DES for FIPS complaince, but it's actually the fact that SSL 3.0 is enabled.


Top
   
PostPosted: Sun May 04, 2014 12:50 am 
Offline
Senior Member

Joined: Mon Jul 05, 2010 5:13 pm
Posts: 392
To clarify, you're suggesting SSL 3.0 should be disabled?

- Les


Top
   
PostPosted: Sun May 04, 2014 12:51 am 
Offline
Senior Newbie

Joined: Thu May 01, 2014 12:25 pm
Posts: 5
Correct. As I understand, that allows the linode nodebalancers as they are to become FIPS ready (compliance is a different matter entirely).


Top
   
PostPosted: Sun May 04, 2014 12:53 am 
Offline
Senior Newbie

Joined: Thu May 01, 2014 12:25 pm
Posts: 5
http://www.rapid7.com/db/vulnerabilities/sslv2-enabled

"Note that neither SSLv2 nor SSLv3 meet the U.S. FIPS 140-2 standard, which governs cryptographic modules for use in federal information systems. Only the newer TLS (Transport Layer Security) protocol meets FIPS 140-2 requirements."


Top
   
PostPosted: Sun May 04, 2014 12:56 am 
Offline
Senior Newbie

Joined: Thu May 01, 2014 12:25 pm
Posts: 5
I guess one thing to consider is it does break IE 6 compatibility. However, that's not something I care about a whole lot personally. :)

Thanks for at least looking into it, whatever y'all decide.


Top
   
PostPosted: Sun May 04, 2014 12:57 am 
Offline
Senior Member

Joined: Mon Jul 05, 2010 5:13 pm
Posts: 392
Removing SSLv3 support would prevent any NodeBalancer HTTPS users from communicating with IE on Windows XP. Despite its recent EOL, a significant part of people are in that spot, to the point that it's not feasible to disable SSLv3. To note, pretty much every browser newer than that uses TLS of some variety.

- Les


Top
   
PostPosted: Sun May 04, 2014 1:47 am 
Offline
Senior Member

Joined: Fri Jul 03, 2009 2:31 am
Posts: 54
ICQ: 897607
It's not just browser compatibility. Some language client libraries still need SSLv3, for example whichever Ruby library is being used by stripe.com for their callbacks. Thus disabling SSLv3 will prevent stripe callbacks from working. Of course those of us in that situation will just continue using our own SSL stacks instead of nodebalancer... or at least not have the callback destination linode behind nodebalancer.


Top
   
PostPosted: Sun May 04, 2014 2:27 am 
Offline
Senior Member

Joined: Sat May 03, 2008 4:01 pm
Posts: 567
Website: http://www.mattnordhoff.com/
akerl, IE on XP supports TLS 1.0, at least sometimes. SSL Labs says that IE 8 does, and I believe even IE 6 does sometimes. (I don't know how many times, though.)

I wonder if NodeBalancers should have a "higher security" checkbox, but it seems like a recipe for user confusion and checkboxitis.

-- mnordhoff, who doesn't use NodeBalancers, speaking from an armchair.

Edit: IE 6 has a TLS 1.0 checkbox. #linode says it's always off by default, though. I had hoped the situation was better, but I didn't know.

_________________
Matt Nordhoff (aka Peng on IRC)


Top
   
PostPosted: Sun May 04, 2014 8:47 am 
Offline
Senior Member

Joined: Mon Jul 05, 2010 5:13 pm
Posts: 392
IE6 does have the checkbox, but I imagine the overlap of "people who check the advanced settings for security enhancements" and "people running IE6 on XP" is small :P

For what it's worth, the reason NodeBalancers (like Linode's other HTTPS sites) have the cipher/protocol/header layout they do now is because we put a lot of thought into making them as strong as possible while ensuring backwards compatibility. Once we get to a place where we can safely remove SSLv3, it will be gone.

- Les


Top
   
PostPosted: Sun May 04, 2014 9:03 am 
Offline
Senior Member

Joined: Sat May 03, 2008 4:01 pm
Posts: 567
Website: http://www.mattnordhoff.com/
akerl wrote:
IE6 does have the checkbox, but I imagine the overlap of "people who check the advanced settings for security enhancements" and "people running IE6 on XP" is small :P

Yeah. I was hoping it had gotten turned on by default at some point. :(

akerl wrote:
For what it's worth, the reason NodeBalancers (like Linode's other HTTPS sites) have the cipher/protocol/header layout they do now is because we put a lot of thought into making them as strong as possible while ensuring backwards compatibility. Once we get to a place where we can safely remove SSLv3, it will be gone.

That's good to know. I'm glad it's on your radar. With IE 6 and Stripe and goddess knows what else, I fear there will always be somebody who demands it, though.

BTW I ♥ ♥ ♥ you for disabling RC4. But I'm a dork.

_________________
Matt Nordhoff (aka Peng on IRC)


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group