SLES-SP4 Apache vunrablility to SSL-RENEGOTIATION

As it seems Suse did not backport the SSLinsecureRenegotiation directive
into the SLES10-SP4 Apache for now
They did backport the option into the openssl package thoucht, but how
could i use it on sles-stock apache?
With the open access to the THC DOS tool it’s getting very risky to
have a ssl server on SLES10:


Thanks for considering the security of your system. Unfortunately this
topic is a bit tricky. We did not backport the SSLInsecureRenegotiation
option, but we disabled insecure renegotiations completely (without an
option to turn it back on). This is however unrelated to the DoS issue
you’re talking about. that one is not about insecure renegotiations, but
about being able to trigger excessive amount of secure renegotiations
continuously on the server, so even if the option would be available, it
would not help.

We’re working with high priority on an update that will address the DoS
issue. The links to that will appear here: and here: and can be installed
like normal via your regular maintenance update methods or ‘NOVELL:
Patch Finder’


