Plesk/Qmail PCI DSS issue

General Discussion of atomic repo and development projects.

Ask for help here with anything else not covered by other forums.
RichardM
Forum User
Forum User
Posts: 69
Joined: Sun Apr 20, 2008 2:51 pm

Plesk/Qmail PCI DSS issue

Unread post by RichardM »

I have run a scanner on my server to test for PCI DSS compliance and I have got rid of all the issues - except one!

The issue is Qmail on port 465 accepting SSLv2 and weak ciphers.

I notice that ASL takes care of Plesk admin doing this in /usr/local/psa/admin/conf/httpsd.asl.include:
SSLCipherSuite ALL:!ADH:!LOW:!SSLv2:!EXP:+HIGH:+MEDIUM
SSLProtocol all -SSLv2
Is there a way to fix Qmail likewise? (Hopefully a way that won't risk breaking the Plesk/Qmail setup!)
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Unread post by scott »

No, but thats a great idea. I'll add it to the feature request list!
Post Reply