[GH-ISSUE #239] Default installation is vulnarable to BEAST attack #135

Closed
opened 2026-02-26 09:36:50 +03:00 by kerem · 3 comments
Owner

Originally created by @XenonOrion on GitHub (Apr 10, 2020).
Original GitHub issue: https://github.com/ONLYOFFICE/Docker-DocumentServer/issues/239

As TLS 1.0 is still supported, the Document Server will be vulnerable to the Beast Attack.

Is there a reason for the choice to keep TLS 1.0 enabled, can there be an option to disable this?

Originally created by @XenonOrion on GitHub (Apr 10, 2020). Original GitHub issue: https://github.com/ONLYOFFICE/Docker-DocumentServer/issues/239 As `TLS 1.0` is still supported, the Document Server will be vulnerable to the [Beast Attack](https://blog.qualys.com/ssllabs/2013/09/10/is-beast-still-a-threat). Is there a reason for the choice to keep TLS 1.0 enabled, can there be an option to disable this?
kerem 2026-02-26 09:36:50 +03:00
Author
Owner

@SuperSandro2000 commented on GitHub (Apr 11, 2020):

While we are at it can we add an option to disable TLS 1.1?

<!-- gh-comment-id:612303829 --> @SuperSandro2000 commented on GitHub (Apr 11, 2020): While we are at it can we add an option to disable TLS 1.1?
Author
Owner
<!-- gh-comment-id:2461435049 --> @igwyd commented on GitHub (Nov 7, 2024): This has been fixed https://github.com/ONLYOFFICE/document-server-package/blob/master/common/documentserver/nginx/ds-ssl.conf.tmpl.m4#L46
Author
Owner

@Rita-Bubnova commented on GitHub (Nov 7, 2024):

I close this issue. Feel free to comment or reopen it if you got further questions.

<!-- gh-comment-id:2461562174 --> @Rita-Bubnova commented on GitHub (Nov 7, 2024): I close this issue. Feel free to comment or reopen it if you got further questions.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/Docker-DocumentServer-ONLYOFFICE#135
No description provided.