versatica/OverSIP

TLSv1.0 Vulnerability being detected at 5061 port

looneyapurv opened this issue · 0 comments

I changed the configuration for TLS Version in OverSIP/lib/oversip/sip/listeners/tls_client.rb & OverSIP/lib/oversip/sip/listeners/tls_server.rb files with **:ssl_version => %w(tlsv1_2)** but this madate for negotiation with only TLSV1_2 ciphers seems to work only with port 10443 and I'm still receiving open vulnerabilities on 5061 like

Negotiated with the following insecure cipher suites: TLS 1.0 ciphers: TLS_RSA_WITH_IDEA_CBC_SHA