Choose SSL or TLS

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
lyttek
Posts: 2
Joined: Tue Oct 21, 2014 6:18 pm

Choose SSL or TLS

Post by lyttek » Tue Oct 21, 2014 6:25 pm

From section 3.2 of the manual:

Intermediate Layer of VPN Tunneling Protocol

Both SSL 3.0 and TLS 1.0 are supported. User can choose which protocol to use. SSL is Secure Socket Layer protocol. TLS is Transport Layer Security protocol. Both of them are widely used in the Internet, and the safety and reliability are proved for more decades by standing despite everyone's mercilessly analysis who is engaging the cryptography science and industry.


I've been poking around both the server and client side of things and cannot find a specific reference for this in either GUI or config.

There are two separate options that I have seen: "Don't use TLS 1.0" and "Encrypt VPN Session with SSL". It would seem that using the latter would make the first option a moot point?

How can we disable SSL on the server and use only TLS?

dnobori
Posts: 228
Joined: Tue Mar 05, 2013 10:04 am

Re: Choose SSL or TLS

Post by dnobori » Wed Oct 22, 2014 4:19 pm


lyttek
Posts: 2
Joined: Tue Oct 21, 2014 6:18 pm

Re: Choose SSL or TLS

Post by lyttek » Wed Oct 22, 2014 4:25 pm

Excellent!

PacoBell
Posts: 15
Joined: Tue Mar 24, 2015 11:45 pm

Re: Choose SSL or TLS

Post by PacoBell » Mon Mar 30, 2015 12:17 am

I'm confused about the "Don't use TLS 1.0" option. Does that apply specifically and only to TLS 1.0 (to mitigate the BEAST attack) or does it also disable TLS 1.2? The latter would be obviously undesirable.

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: Choose SSL or TLS

Post by thisjun » Wed Apr 08, 2015 5:12 am

SoftEther VPN doesn't support TLS 1.2.

KFrische
Posts: 5
Joined: Wed Jun 24, 2015 11:39 am

Re: Choose SSL or TLS

Post by KFrische » Wed Jun 24, 2015 11:47 am

There are security weaknesses in TLS v1.0 and TLS v1.1.

Is there a timeline to replace the TLS v1.0 with TLS v.1.2 ??

lovether
Posts: 5
Joined: Thu Jan 14, 2016 9:52 am

Re: Choose SSL or TLS

Post by lovether » Thu Jan 14, 2016 10:08 am

KFrische wrote:
> There are security weaknesses in TLS v1.0 and TLS v1.1.
>
> Is there a timeline to replace the TLS v1.0 with TLS v.1.2 ??

Now you can build your own VPN Server with TLSv1.2 enabled referring to this PR on github.
https://github.com/SoftEtherVPN/SoftEtherVPN/pull/208

rtau-t24
Posts: 4
Joined: Fri Nov 06, 2015 6:04 am

Re: Choose SSL or TLS

Post by rtau-t24 » Mon Mar 14, 2016 5:21 am

thisjun wrote:
> SoftEther VPN doesn't support TLS 1.2.

Please take a look at https://github.com/SoftEtherVPN/SoftEtherVPN/pull/208, see whether it is sufficient to allow SoftEther VPN to support TLS 1.2.

Thanks.

Post Reply