How to close the SSL V3.0 "Poodle" Vulnerability - CVE-2014-3566
Hi,
We have scanned totally 2 nodes RAC servers for vulnerabilities. There are some medium level vulnerabilities such as SSLv3 disable and Cluster certificate changing recommendations. We have installed the TFA(Trace File Analyzer) for this problem. How to resolve the problem using TFA? But we scan again the system and have same the vulnerabilities. How to close the related issues? The vulnerabilities as the below;
Thanks,
How should we change the related RAC Certificate?
SSL Self-Signed Certificate
Solution
Purchase or generate a proper certificate for this service.
How to disable SSLv3? I think this need to be mod_ssl installation, but how is it possible without mod_ssl ?