Securing SSL/TLS with Secure Renegotiation

Analysis
Mar 5, 20101 min

A recently-exposed a flaw in the current standard for the SSL/TLS protocol allows “man-in-the-middle” attacks, but fortunately there’s an interim fix included in OpenSSL release 0.9.8l. This article describes the solution and provides links to additional resources.