<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx</link><description>Understanding Problems with MS10-049, KB 980436 and IETF RFC5746 
 Microsoft released a Security update MS10-049: Vulnerabilities in SChannel could allow remote code execution. This update patches vulnerabilities in SChannel (TLS) that can be exploited</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx#10355251</link><pubDate>Tue, 02 Oct 2012 19:38:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10355251</guid><dc:creator>Jeff  Sanders</dc:creator><description>&lt;p&gt;Hi Dan,&lt;/p&gt;
&lt;p&gt;This article should be fairly complete however you can certainly open a support case to discuss this further.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/oas"&gt;support.microsoft.com/oas&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;-Jeff&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10355251" width="1" height="1"&gt;</description></item><item><title>re: Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx#10355245</link><pubDate>Tue, 02 Oct 2012 19:14:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10355245</guid><dc:creator>Dan Martin</dc:creator><description>&lt;p&gt;It looks like we are bumping into this issue as well.&lt;/p&gt;
&lt;p&gt;JPSanders, is there any way that we can discuss this further via PM? &amp;nbsp;My team has several questions regarding the behavior of this patch and how we can work around the issues we are seeing.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10355245" width="1" height="1"&gt;</description></item><item><title>re: Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx#10086030</link><pubDate>Thu, 04 Nov 2010 11:39:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10086030</guid><dc:creator>Jeff  Sanders</dc:creator><description>&lt;p&gt;That server is built on open source I believe. &amp;nbsp;The problem would be with the openSSL library. &amp;nbsp;He can build get the openSSL library himself and rebuild the code for the server. &amp;nbsp;He can also request a fix from the vendor. &amp;nbsp;Every client that calls the server could also be patched as an alternative. &amp;nbsp;Obviously patching every client is not a great idea gut it is possible.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10086030" width="1" height="1"&gt;</description></item><item><title>re: Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx#10085856</link><pubDate>Thu, 04 Nov 2010 02:37:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10085856</guid><dc:creator>Asher T</dc:creator><description>&lt;p&gt;I&amp;#39;ve got a customer who&amp;#39;s using webMethods Integration Server and he&amp;#39;s facing this issue as well. Does he need to request a patch for webMethods? Also does your workaround need to be done at client side? It&amp;#39;s a Win2k3 x86 Server SP3 for the server but client side could be any desktop OS.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10085856" width="1" height="1"&gt;</description></item><item><title>re: Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx#10071263</link><pubDate>Mon, 04 Oct 2010 16:55:25 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10071263</guid><dc:creator>Jeff  Sanders</dc:creator><description>&lt;p&gt;Mike, It should!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10071263" width="1" height="1"&gt;</description></item><item><title>re: Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx#10064308</link><pubDate>Fri, 17 Sep 2010 23:29:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10064308</guid><dc:creator>Mike B</dc:creator><description>&lt;p&gt;Does the UseScsvForTls registry setting work on Windows 2008R2?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10064308" width="1" height="1"&gt;</description></item><item><title>re: Understanding Problems with MS10-049, KB 980436 and IETF RFC5746</title><link>http://blogs.msdn.com/b/jpsanders/archive/2010/09/08/understanding-problems-with-ms10-049-kb-980436-and-ietf-rfc5746.aspx#10060685</link><pubDate>Sat, 11 Sep 2010 13:20:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10060685</guid><dc:creator>Alan McF</dc:creator><description>&lt;p&gt;For those who haven&amp;#39;t read the RFC Draft, SCSV stands for &amp;quot;Signalling Cipher Suite Value&amp;quot;:&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;quot;This SCSV is not a true cipher suite ... instead it has the same semantics as an empty &amp;quot;renegotiation_info&amp;quot; extension, ...&lt;/p&gt;
&lt;p&gt; &amp;nbsp; (&amp;quot;Because SSLv3 and TLS implementations reliably ignore unknown cipher suites, the SCSV may be safely sent to any server.&amp;quot;)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10060685" width="1" height="1"&gt;</description></item></channel></rss>