I am trying to get PCI compliance, I have everything sorted except for the following error on port 2222
Title: TLS Protocol Session Renegotiation Security Vulnerability
Impact: The vulnerability allows man-in-the-middle attack.
Resolution: For OpenSSL, [http://www.openssl.org/source/] upgrade to 0.9.8l or higher.
For Microsoft IIS web servers, install the appropriate patch available through [http://technet.microsoft.com/en- us/security/bulletin/MS10-049] Microsoft Security Bulletin 10-049.
For other types of products, consult the product documentation.
Risk Factor: Medium/ CVSS2 Base Score: 5.8
(AV:N/AC:M/Au:N/C:N/I
/A
) CVE: CVE-2009-3555 BID: 36935
The OpenSSL version on the server is 1.0.1, I assume this is something that needs to be configured in directadmin.conf but I am not sure what it needs to be.
Any help would be greatly appreciated.
Title: TLS Protocol Session Renegotiation Security Vulnerability
Impact: The vulnerability allows man-in-the-middle attack.
Resolution: For OpenSSL, [http://www.openssl.org/source/] upgrade to 0.9.8l or higher.
For Microsoft IIS web servers, install the appropriate patch available through [http://technet.microsoft.com/en- us/security/bulletin/MS10-049] Microsoft Security Bulletin 10-049.
For other types of products, consult the product documentation.
Risk Factor: Medium/ CVSS2 Base Score: 5.8
(AV:N/AC:M/Au:N/C:N/I


The OpenSSL version on the server is 1.0.1, I assume this is something that needs to be configured in directadmin.conf but I am not sure what it needs to be.
Any help would be greatly appreciated.