AnsweredAssumed Answered

Zombie 3DES ciphers?

Question asked by Whex on Mar 4, 2015
Latest reply on Mar 4, 2015 by Whex

Qualys SSL Labs - Projects / SSL Server Test / duckweb.uoregon.edu  (Dev)

 

Qualys SSL Labs - Projects / SSL Server Test / duckweb.uoregon.edu   (Prod)

 

 

The server only advertises RC4 support and refuses connection from openssl with 'DES-CBC3-SHA' as a cipher.  Nonetheless, the SSL Test lists 3DES as the negotiated cipher for several clients (e.g. Android 4.3).  Is this by design?

 

 

Thanks,

Whex

Outcomes