Mike Grabbe
06/16/2023, 2:05 PMNate
06/16/2023, 2:14 PMMike Grabbe
06/16/2023, 2:18 PMRUN sed -i 's/TLSv1\.2/TLSv1.0/g' /etc/ssl/openssl.cnf
RUN sed -i 's/DEFAULT@SECLEVEL=2/DEFAULT@SECLEVEL=1/g' /etc/ssl/openssl.cnf
With OpenSSL v3.0.9, the config file is structured differently, and we need to append these config options to achieve the same security level downgrade:
[openssl_init]
ssl_conf = ssl_sect
[ssl_sect]
system_default = system_default_sect
[system_default_sect]
CipherString = DEFAULT@SECLEVEL=0
Mike Grabbe
06/16/2023, 2:19 PM