FastDomain Web Hosting Help

Disable SSLv3 on a VPS or Dedicated Server

Overview

This article will explain how to disable SSLv3 on a VPS or Dedicated server. This can help you avoid issues with vulnerabilities in SSLv3.

Click on any of the sections to jump to that point in the guide.



What You Need

  • The password for the root user on your server.

Login to the WHM

You will need to be able to login to WHM on your server. This requires knowing the root password for your server. If you don't know the root password or haven't set one up, please see https://my.FastDomain.com/hosting/help/whm-login#root-password.

  1. Login to the WHM by going to yourdomain.com/whm in a browser. Replace yourdomain.com with your domain name.
  2. Once you get to the login page, enter your username and password.
    The WHM login page.
    The WHM login page.
  3. You may see a page titled "Feature Showcase". If so, click on Exit to WHM at the bottom of the page.
    The Feature Showcase page with 'Exit to WHM' spotlighted.
    The Feature Showcase page with "Exit to WHM" spotlighted.

Open the Apache Settings

  1. In the search bar at the top left of the WHM, type "Apache".
    Searching Apache in the WHM.
    Searching Apache in the WHM.
  2. In the search results, click on "Apache Configuration".

Change the SSL Cipher and Protocol Settings

  1. On Apache Configuration page, click on Global Configuration
    The global configuration.
    The global configuration.
  2. The first option should be SSL Cipher Suite, Select the 3rd option then copy this text into the box:
    ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP:!kEDH
    The SSL Cipher Suite settings.
    The SSL Cipher Suite settings.
  3. Under SSL/TLS Protocols, make sure the default setting, All -SSLv2 -SSLv3 is selected.
    The SSL/TLS Protocol settings.
    The SSL/TLS Protocol settings.
  4. Scroll to the bottom of the page and click the Save button.
    The save button.
    The save button.
  5. Click the Rebuild Configuration and Restart Apache button.
    The Rebuild Configuration and Restart Apache button.
    The Rebuild Configuration and Restart Apache button.
A successful rebuild.
A successful rebuild.

Note: After following these steps it may be necessary to add "Options +FollowSymLinks" to the .htaccess file for your site.

Test the Configuration

To test that SSL is disabled you run this command:
curl -IL –sslv3 https://domain.com
Note: replace domain.com with the domain for your site.
If SSLv3 has been disabled you should see a message like this:

curl: (35) error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure
Knowledgebase Article 25,436 views bookmark tags: dedi dedicated ssl vps


Was this resource helpful?

Did this resolve your issue?


Please add any other comments or suggestions about this content:





Recommended Help Content

This article discusses some measures you can take to secure a Dedicated or VPS server
Knowledgebase Article 22,030 views tags: dedi security vps

How to fix inaccessible backups on Dedicated or VPS servers due to backup size.
Knowledgebase Article 21,845 views tags: backup dedi dedicated inaccessible loop stuck vps

How do I use the free shared SSL Certificate?
Knowledgebase Article 568,358 views tags: certificate path shared ssl

Related Help Content

This article will show a way to protect specific pages of your website with SSL. This may have benefits for SEO and can be used on pages that contain forms, shopping carts or any other page where users might enter sensitive information.
Knowledgebase Article 41,981 views tags: htaccess pages specific ssl

This article will explain how to use RoR through passenger on a hosting account
Knowledgebase Article 90,235 views tags: dedicated passenger redmine ruby vps

This article explains how to download a copy of your SSL certificate.
Knowledgebase Article 93,531 views tags: certificate move ssl

How to renew an existing SSL certificate--or purchase a new one, within your cPanel
Knowledgebase Article 175,646 views tags: cert certificate layer secure security socket ssl

I need to have an SSL 3rd Party Certificate installed for my domain.
Knowledgebase Article 316,948 views tags: certificate ssl

How do I disable CloudFlare for my domain?
Knowledgebase Article 61,764 views tags: cloudflare disable

Where do I get a copy of the site seal for my SSL I purchased through FastDomain?
Knowledgebase Article 234,109 views tags: cert image logo seal secure ssl

I need to have an SSL Self-Signed Certificate installed for my domain.
Knowledgebase Article 188,159 views tags: secure ssl