{"id":3236,"date":"2011-12-07T21:29:26","date_gmt":"2011-12-07T21:29:26","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=3236"},"modified":"2015-09-09T19:37:03","modified_gmt":"2015-09-09T11:37:03","slug":"sslyze-fast-and-full-featured-ssl-configuration-scanner","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2011\/12\/sslyze-fast-and-full-featured-ssl-configuration-scanner\/","title":{"rendered":"sslyze – Fast and Full-Featured SSL Configuration Scanner"},"content":{"rendered":"

Transport Layer Security (TLS), commonly called SSL, is one of the most widely used protocols to secure network communications. As costs fall and user security and privacy expectations rise companies are deploying it more widely every year. Attacks against the CA system, SSL implementation flaws and aging protocol versions have grabbed news headlines, bringing attention to weak configurations, and the need to avoid them. Additionally, server misconfiguration has always greatly increased the overhead caused by SSL, slowing the transition to improved communications security.<\/p>\n

To help improve system configurations, iSEC is releasing the free software \u201cSSLyze\u201d tool. They have found this tool helpful for analyzing the configuration of SSL servers and for identifying misconfiguration such as the use of outdated protocol versions, weak hash algorithms in trust chains, insecure renegotiation, and session resumption settings.<\/p>\n