AnsweredAssumed Answered

SSL Labs Test fails if I disallow SSLv3

Question asked by Sylvain Munaut on Oct 16, 2014
Latest reply on Oct 16, 2014 by Sylvain Munaut



I modified the source code of our SSL front end to disable v3 using SSL_OP_NO_SSLv3 flag (in addition to the v2 one which was there already).


When I do this, the SSL Labs test just fails all together, but using a browser it works just fine. Trying with openssl s_client shows SSLv2/3 fails and TLS works.

And when I runned the test before disabling v3, it correctly showed that TLS was used for all browsers except for the IE6/XP combination.


What could be the issue ?