A recently-exposed a flaw in the current standard for the SSL/TLS protocol allows “man-in-the-middle” attacks, but fortunately there’s an interim fix included in OpenSSL release 0.9.8l. This article describes the solution and provides links to additional resources.
Securing SSL/TLS with Secure Renegotiation
Analysis
Mar 5, 20101 min




