PDA

View Full Version : PCI Scan - Anyone With Experience w/ Powweb


Cyberlore
12-22-08, 11:30 PM
I am attempting to pass a PCI-DSS compliance scan for our site but I receive a warning that "The remote host supports the use of anonymous SSL ciphers."

My chat with tech support failed to yield any helpful information on this warning. Is there anything that can be done on a site-by-site basis (OpenSSL overrides) or am I out of luck short of getting powweb to correct the issue on their servers?

Thanks!

Croc Hunter
12-23-08, 02:42 AM
SSL are not available here at this time for any site Cyberlore sorry. You may of course make a formal request for it to be made available via the OPS support console.

boywaja
12-30-08, 02:34 AM
SSL are not available here at this time for any site .

SSL is available using the wildcard cert. https://%username%.powweb.com .

AFAIK ssl config is a server wide setting and not one you can implement yourself.

IMO they should already have disabled anonymous SSL ciphers. All I can suggest is you ask support nicely to actually talk to the backend engineer who will understand what you are asking.