Sunday, January 19, 2020

PFS(Perfect Forward Secrecy)




PFS is a feature of specific key agreement protocols that gives assurance that session keys will not be compromised even if the private key is compromised.

There is no one click enabling for PFS. You have to choose the right cipher suites in order to have/achieve PFS. You should make sure Diffie Helman is chosen as key exchange algorithm.

TLS/SSL Vulnerabilities

POODLE:  The SSL 3.0 vulnerability is in the Cipher Block Chaining (CBC) mode. Block ciphers require blocks of fixed length. If data in th...