Is Hiawatha 9.8 vulnerable to SSL 3.0 (Poodle) bug? Several tests (designed for Apache) return true on my websites. If so how to disable SSL 3.0? Thanks.
Hugo Leisink
16 October 2014, 19:18
No, SSL3.0 is disabled by default. Hiawatha is only vulnerable for this if you've explicitly enabled SSL3.0 via MinSSLversion = SSL3.0.
Viren
16 October 2014, 19:30
Thanks! Good to know! Is there a Hiawatha specific test to verify? My superiors will ask for this.