Well that depends on what kind of client and server you are using! Usually, there is a list of algorithms on both sides (client and server), list that can be set up by the user/administrator. During phase 1 of the Handshake, client sends a list to the server, ordering his wishes. Then, the server looks at his own list, and sends back a reply ASAP a match has been found...so depends on the configuration of the both sides!:)
-----Message d'origine-----
De : Abhishek Kumar [mailto:abhishek.kumar_at_paladion.net]
Envoyé : mardi 23 mars 2004 14:31
À : webappsec_at_securityfocus.com
Objet : SSL version selection query
Hello,
I have a query regarding SSL. There is a web server on which both SSLv2
and SSLv3 are enabled. Along with this all the Cipher suites (including
low strength) are also enabled on this server.
A client is using a browser which supports both SSLv2 and SSLv3, with
high strength encryption.
My question is:
What version of SSL and Cipher suite will be chosen by default? Will it
always be SSLv3 with maximum strength encryption ? Or is there a
situation where SSLv2 can also be selected with some low strength Cipher
suite.
Thanks
-Abhishek
Received on Mar 23 2004