Incorrect use of SSL options

Bug #1383415 reported by Marc Deslauriers
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
SpamAssassin
Unknown
Unknown
spamassassin (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

The following commit is incorrect:

https://github.com/apache/spamassassin/commit/87caaa37615318eaa8940a5c6f3d6065cedd86d1

This makes spamassassin use SSLv3 by default, and does _not_ do what is documented:

"The default, B<sslv3>, is the most flexible, accepting a SSLv3 or
higher hello handshake, then negotiating use of SSLv3 or TLSv1
protocol if the client can accept it."

Changed in spamassassin (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.