Hide Forgot
Description of problem: SSL 3.0 and TLS 1.0 are not considered secure anymore for quite some time so we should not listen on them Version-Release number of selected component (if applicable): mod_ssl-2.4.6-40.el7_2.4.x86_64 How reproducible: always Steps to Reproduce: 1. install httpd with mod_ssl on fresh RHEL 7 system 2. check SSLProtocol directive in /etc/httpd/conf.d/ssl.conf 3. Actual results: SSLProtocol all -SSLv2 Expected results: SSLProtocol +TLSv1.2 +TLSv1.1 or SSLProtocol all -SSLv2 -SSLv3 -TLSv1 Additional info: related RHV bug (its TLS > 1.0 intolerance): Bug 1387996, similar bugs in other products may also appear.