<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : Perfect Forward Secrecy</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : Perfect Forward Secrecy]]></description>
  <pubDate>Wed, 20 May 2026 12:43:57 +0000</pubDate>
  <lastBuildDate>Thu, 21 May 2015 22:45:12 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=7099</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[Perfect Forward Secrecy :  I would not leave SSLv3 enabled...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14740&amp;title=perfect-forward-secrecy#14740</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 21 May 2015 at 10:45pm<br /><br />I would not leave SSLv3 enabled after just disabling the CBC ciphers. That pretty much just leaves SSLv3 to use the RC4 ciphers, which are even more exploitable than the CBC. You really should disable SSLv3 in its entirety to avoid any relatively simple exploits.<div><br></div><div>For the syntax - yes, it is the OpenSSL one since SpamFilter's SSL libraries are based on that. T<span style="line-height: 1.4;">he cipher list you're using looks pretty good. Another one we've tested for a while with decent results is this one:</span></div><div><font size="1" color="#000066">AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:HIGH:!MD5:!aNULL:!EDH</font></div><div><br></div><div><br></div>]]>
   </description>
   <pubDate>Thu, 21 May 2015 22:45:12 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14740&amp;title=perfect-forward-secrecy#14740</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : I found the SSLCipherList is openSSL...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14739&amp;title=perfect-forward-secrecy#14739</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 21 May 2015 at 12:27am<br /><br />I found the SSLCipherList is openSSL based.<div><br></div><div>Some instructions here for anyone who is interested:</div><div><br></div><div><a href="http://www.openssl.org/docs/apps/ciphers.html" target="_blank" rel="nofollow">https://www.openssl.org/docs/apps/ciphers.html</a><br><div><br></div><div>I had no luck leaving SSLv3 enabled and just disabling&nbsp;SSLv3+CBC, the vulnerability tester I was using always complains if SSLv3 is enabled at all.</div><div><br></div><div>I have ended up with this for the time being, will see what the fallout is from this.</div><div><br></div><div>SSLCipherList=AES:ALL:!aNULL:!eNULL:!DES:+RC4:!ECDHE-RSA-RC4-SHA:!RC4-SHA:!RC4-MD5:@STRENGTH</div></div>]]>
   </description>
   <pubDate>Thu, 21 May 2015 00:27:51 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14739&amp;title=perfect-forward-secrecy#14739</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : Can you provide some more information...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14738&amp;title=perfect-forward-secrecy#14738</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 20 May 2015 at 11:23pm<br /><br />Can you provide some more information on how to use the SSLCiperList, looks like the following was added to the INI in a recent version update.<div><br></div><div>SSLCipherList=AES:ALL:!aNULL:!eNULL:+RC4:@STRENGTH</div><div><br></div><div>Where do we find out the syntax for this and what we can add? &nbsp;Is it open ssl or something?</div><div><br></div><div>Like others have mentioned in this board I also have problems if I disable anything :-(</div><div><br></div><div>If I disable TLS 1, someone is going to complain. &nbsp;The issue is probably the sending server, but I look like the badguy so I leave it enabled.</div><div><br></div><div>The recent version disabled SSL3 due to the POODLE vulnerability. &nbsp;Guess what happens, I start getting email from people that they can't get email from someone. &nbsp;It is happening on a large enough scale that I must enable SSL3 again.</div><div><br></div><div>From my POOLE reading, it looks like if you disable SSLv3+CBC you might not be vulnerable? &nbsp;I would like to try and disable the CBC cipher but no idea how to go about it.</div><div><br></div>]]>
   </description>
   <pubDate>Wed, 20 May 2015 23:23:27 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14738&amp;title=perfect-forward-secrecy#14738</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : Hi Roberto, it worksI hope the...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14737&amp;title=perfect-forward-secrecy#14737</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1357">ois</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 11 May 2015 at 5:32am<br /><br />Hi Roberto, it works&nbsp;<img src="https://www.logsat.com/spamfilter/forums/smileys/smiley1.gif" border="0" alt="Smile" title="Smile" /><br><br>I hope the goverment is also satisfied. We will see. Tnx for your kindly support and help us, to hold this deadline. <img src="https://www.logsat.com/spamfilter/forums/smileys/smiley20.gif" border="0" alt="Thumbs Up" title="Thumbs Up" /><br><br>Regards, Fritz<br>OIS<br><br><br>]]>
   </description>
   <pubDate>Mon, 11 May 2015 05:32:36 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14737&amp;title=perfect-forward-secrecy#14737</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : ois,FYI we have pre-released SpamFilter...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14736&amp;title=perfect-forward-secrecy#14736</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 10 May 2015 at 9:55pm<br /><br />ois,<div><br></div><div>FYI we have pre-released SpamFilter v4.7.0.136 in the registered user area - this build supports PFS as requested.</div>]]>
   </description>
   <pubDate>Sun, 10 May 2015 21:55:22 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14736&amp;title=perfect-forward-secrecy#14736</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : nice!   ]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14734&amp;title=perfect-forward-secrecy#14734</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1357">ois</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 07 May 2015 at 6:46am<br /><br />nice!&nbsp;]]>
   </description>
   <pubDate>Thu, 07 May 2015 06:46:40 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14734&amp;title=perfect-forward-secrecy#14734</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : ois,We have good news on the FPS...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14732&amp;title=perfect-forward-secrecy#14732</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 06 May 2015 at 11:07pm<br /><br />ois,<div><br></div><div>We have good news on the FPS ciphers. We're testing an internal alpha version now that is able to support them. We will likely release it publicly within the next 3-4 days.&nbsp;</div>]]>
   </description>
   <pubDate>Wed, 06 May 2015 23:07:41 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14732&amp;title=perfect-forward-secrecy#14732</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : ois,In our internal alpha version...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14725&amp;title=perfect-forward-secrecy#14725</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 29 April 2015 at 4:05pm<br /><br />ois,<div><br></div><div>In our internal alpha version we added the ability to have user-configurable cipher lists, which will allow to obtain much higher security as in this sample report below.&nbsp;<span style="line-height: 1.4;">We're still working to add FPS support, but are not there yet - there are good chances we'll be able to meet your deadline, but I cannot say for certain at this point.</span></div><div><span style="line-height: 1.4;"><br></span></div><div><span style="color: rgb245, 245, 245; font-family: M&#111;naco; font-size: 10px; line-height: normal; : rgb0, 0, 0;">c:~ c$ ~/testssl.sh --starttls smtp 10.211.55.7:25</span></div><div><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">#########################################################</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">testssl.sh v2.2&nbsp; (https://testssl.sh)</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #ffffff">(</span>$Id: testssl.sh,v 1.151 2014/12/08 09:32:50 dirkw Exp $<span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #ffffff">)</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">&nbsp;&nbsp; This program is free software. Redistribution +&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">&nbsp;&nbsp; modification under GPLv2 is permitted.&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">&nbsp;&nbsp; USAGE w/o ANY WARRANTY. USE IT AT YOUR OWN RISK!</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">&nbsp;Note: you can only check the server with what is</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">&nbsp;available (ciphers/protocols) locally on your machine!</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb255, 255, 255; : rgb0, 0, 0;">#########################################################</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Using "OpenSSL 1.0.2a 19 Mar 2015" from</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;cmctrf2.local:/usr/local/bin/openssl</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;(built: "reproducible build, date unspecified", platform: "darwin64-x86_64-cc")</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; : rgb245, 245, 245;">Testing now (2015-04-29 16:00) ---&gt; 10.211.55.7:25 (10.211.55.7) &lt;---</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;rDNS (10.211.55.7):&nbsp; &nbsp; &nbsp; -&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Couldn't determine what's running on port 25, assuming not HTTP</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb83, 48, 225; : rgb0, 0, 0;">--&gt; Testing Protocols&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb52, 189, 38; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #f5f5f5">&nbsp;SSLv2&nbsp; &nbsp; &nbsp; </span>not offered (OK)&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb52, 189, 38; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #f5f5f5">&nbsp;SSLv3&nbsp; &nbsp; &nbsp; </span>not offered (OK)&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb52, 189, 38; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #f5f5f5">&nbsp;TLSv1&nbsp; &nbsp; &nbsp; </span>offered (OK)&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb52, 189, 38; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #f5f5f5">&nbsp;TLSv1.1&nbsp; &nbsp; </span>offered (OK)&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb52, 189, 38; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #f5f5f5">&nbsp;TLSv1.2&nbsp; &nbsp; </span>offered (OK)&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb83, 48, 225; : rgb0, 0, 0;">--&gt; Testing standard cipher lists&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Null Cipher&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Anonymous NULL Cipher&nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Anonymous DH Cipher&nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;40 Bit encryption&nbsp; &nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb213, 59, 211; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #f5f5f5">&nbsp;56 Bit encryption&nbsp; &nbsp; &nbsp; &nbsp; </span>Local problem: No 56 Bit encryption configured in /usr/local/bin/openssl&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Export Cipher (general)&nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Low (&lt;=64 Bit) &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;DES Cipher &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Triple DES Cipher&nbsp; &nbsp; &nbsp; &nbsp; offered</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Medium grade encryption&nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #ffffff">not offered</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;High grade encryption&nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">offered (OK)&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb83, 48, 225; : rgb0, 0, 0;">--&gt; Testing server defaults (Server Hello)&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Negotiated protocol &nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">TLSv1.2&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Negotiated cipher &nbsp; &nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">AES256-GCM-SHA384&nbsp;</span></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Server key size &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 2048 bit</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;TLS server extensions &nbsp; &nbsp; renegotiation info, session ticket, heartbeat</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;Session Tickets RFC 5077&nbsp; 300 seconds</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;OCSP stapling &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; not offered</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb83, 48, 225; : rgb0, 0, 0;">--&gt; Testing specific vulnerabilities&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb52, 189, 38; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #ffffff">&nbsp;Renegotiation </span><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #f5f5f5">(CVE 2009-3555) &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; </span>Patched Server detected (0,1), probably ok&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #ffffff">&nbsp;CRIME, TLS </span>(CVE-2012-4929)&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #34bd26">not vulnerable (OK)&nbsp;</span> (not using HTTP anyway)</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb83, 48, 225; : rgb0, 0, 0;">--&gt; Testing all locally available ciphers against the server&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">Hexcode&nbsp; Cipher Suite Name (OpenSSL)&nbsp; &nbsp; KeyExch. &nbsp; Encryption Bits</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">-------------------------------------------------------------------------</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x9d &nbsp; &nbsp; AES256-GCM-SHA384&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; AESGCM &nbsp; &nbsp; 256&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x3d &nbsp; &nbsp; AES256-SHA256&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; AES&nbsp; &nbsp; &nbsp; &nbsp; 256&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x35 &nbsp; &nbsp; AES256-SHA &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; AES&nbsp; &nbsp; &nbsp; &nbsp; 256&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x84 &nbsp; &nbsp; CAMELLIA256-SHA&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; Camellia &nbsp; 256&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x9c &nbsp; &nbsp; AES128-GCM-SHA256&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; AESGCM &nbsp; &nbsp; 128&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x3c &nbsp; &nbsp; AES128-SHA256&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; AES&nbsp; &nbsp; &nbsp; &nbsp; 128&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x2f &nbsp; &nbsp; AES128-SHA &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; AES&nbsp; &nbsp; &nbsp; &nbsp; 128&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x41 &nbsp; &nbsp; CAMELLIA128-SHA&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; Camellia &nbsp; 128&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;">&nbsp;x0a &nbsp; &nbsp; DES-CBC3-SHA &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RSA&nbsp; &nbsp; &nbsp; &nbsp; 3DES &nbsp; &nbsp; &nbsp; 168&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb83, 48, 225; : rgb0, 0, 0;">--&gt; Checking RC4 Ciphers&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb52, 189, 38; : rgb0, 0, 0;">no RC4 ciphers detected (OK)&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0;"><span style="font-variant-ligatures: no-comm&#111;n-ligatures; color: #5330e1">--&gt; Testing (Perfect) Forward Secrecy&nbsp; (P)FS)&nbsp;</span> -- omitting 3DES, RC4 and Null Encryption here</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb175, 173, 36; : rgb0, 0, 0;">No PFS available&nbsp;</p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; color: rgb245, 245, 245; : rgb0, 0, 0; min-height: 14px;"><br></p><p style="margin: 0px; font-size: 10px; line-height: normal; font-family: M&#111;naco; : rgb245, 245, 245;">Done now (2015-04-29 16:00) ---&gt; 10.211.55.7:25 (10.211.55.7) &lt;---</p></div><div><br></div>]]>
   </description>
   <pubDate>Wed, 29 Apr 2015 16:05:57 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14725&amp;title=perfect-forward-secrecy#14725</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : Hi Roberto,we have to fix the...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14724&amp;title=perfect-forward-secrecy#14724</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1357">ois</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 29 April 2015 at 8:32am<br /><br />Hi Roberto,<br>we have to fix the PFS-issue until the 10th of may. Otherwise we'll get a lot of trouble with the german goverment. Is it possible to force the PFS fix?<br><br>Regards, Fritz<br>OIS<br>]]>
   </description>
   <pubDate>Wed, 29 Apr 2015 08:32:02 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14724&amp;title=perfect-forward-secrecy#14724</guid>
  </item> 
  <item>
   <title><![CDATA[Perfect Forward Secrecy : We had placed it on hold as we...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14721&amp;title=perfect-forward-secrecy#14721</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7099<br /><strong>Posted:</strong> 23 April 2015 at 10:44pm<br /><br />We had placed it on hold as we recently released a new version of SpamFilter that features a separate GUI to control SpamFilter's service under Windows 2008/2012, in in these versions of Windows managing the SpamFilter service via the Interactive Services Detection screen was very inconvenient.<div><br></div><div>We'll resume to attempt support for this shortly.</div>]]>
   </description>
   <pubDate>Thu, 23 Apr 2015 22:44:47 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7099&amp;PID=14721&amp;title=perfect-forward-secrecy#14721</guid>
  </item> 
 </channel>
</rss>