Commit 5abd23

2025-02-27 10:26:17 Samuli Seppänen: Switch to non-AI version
Security Announcements/SecurityAnnouncement-FREAK.md ..
@@ 1,10 1,10 @@
- The OpenSSL versions included in the official OpenVPN *Windows installers* before 2.3.6-I002/I602 are vulnerable to [FREAK](https://www.smacktls.com/). All users of the official OpenVPN Windows installers are strongly advised to upgrade their OpenVPN installations or take additional steps (see below) to counter the threat. OpenVPN users on UNIX systems usually receive an updated OpenSSL version through their package management system and do not need to update OpenVPN.
+ The OpenSSL versions bundled in official OpenVPN *Windows installers* prior to 2.3.6-I002/I602 are vulnerable to [FREAK](https://www.smacktls.com/). All users of the official OpenVPN Windows installers are encouraged to upgrade their OpenVPN installations or to take other measures (see below) to mitigate the attack. OpenVPN users on *NIX typically get an updated OpenSSL version through their package management system and do not need to update OpenVPN.
- Thankfully, the vulnerability's impact on OpenVPN is relatively minor:
+ Fortunately the vulnerability's impact on OpenVPN is fairly small:
- - If activated, OpenVPN's `tls-auth` feature blocks this attack.
- - Adding `!EXP` to the server-side `tls-cipher` is sufficient to prevent attacks. The recommended `tls-cipher` string is `DEFAULT:!EXP:!LOW:!PSK:!SRP:!kRSA`. This configuration excludes export ciphers, weak ciphers (like DES), and RSA key exchange (note: not RSA authentication), while allowing any future, stronger cipher suites.
- - Clients who want to completely avoid this attack on clients before 2.3.6-I002/I603 can add `!kRSA` to their `tls-cipher` string.
- - An attacker needs to be in a man-in-the-middle position.
- - An attacker must invest time and money per OpenVPN instance (restart) to attack a connection, making this mainly relevant for targeted attacks.
- - OpenVPN consistently offers PFS with its own key exchange mechanism, making it impossible to decrypt sessions before a successful factorization of the temporary export key, even if those connections previously used an RSA_EXPORT cipher.
\ No newline at end of file
+ * If enabled, OpenVPN's tls-auth feature prevents this attack
+ * Adding *!EXP* to the server side tls-cipher is enough to mitigate attacks. The suggested tls-cipher string is *DEFAULT:!EXP:!LOW:!PSK:!SRP:!kRSA*. This disallows export ciphers, weak ciphers (e.g. DES), and RSA key exchange (note: not RSA authentication), but allows any future, stronger cipher suites.
+ * Clients who wish to rule out this attack on clients prior to 2.3.6-I002/I603 can add *!kRSA* to their tls-cipher string
+ * An attacker requires a man-in-the-middle position.
+ * An attacker has to invest time and money per OpenVPN instance (restart) to attack a connection, which makes this relevant for targeted attacks only.
+ * OpenVPN always provides PFS with its own key exchange mechanism, making it impossible to decrypt sessions prior to a successful factorization of the temporary export key, even if those connections already used an RSA_EXPORT cipher.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9