- Posts: 5
- Thank you received: 0
Ask the community, share ideas, and connect with other LimeSurvey users!
Would you mind to elaborate a bit?iqprGmbH wrote: our security consultants asks me to deactivate 3DES.
If I do so, limesurvey doesn't run anymore, even if I don't use encryption features (as far as I know)
So you can't guarantee it, or what does the "depending on the version" mean here? Which version use 3DES and which don't?Depending on the version in use i can assure you that LimeSurvey v3 is not using 3DES anywhere.
iqprGmbH wrote: Dear all,
it is (was) limesurvey 2.67.3 on a Win Server 2012.
I disabled triple DES in the Registry ("HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168")
and afterwards I coud not open any page (not the login, or any other page). I just get a warning, that 3DES is not available.
The PHP/5.3.28 under Windows 2012 is your elephant in the room.iqprGmbH wrote: BTW: I tried to update PHP many times, but wasn't able to do so.
Why should they change annotations of a third party framework (Yii).iqprGmbH wrote: To the developers: If it's true, that limesurvey 3 doesn't use 3DES (and Mcrypt?) it would be great to update the annotations in the php-files.
That's what I thought too!Wonder why the security consulting didn't ask for changing that.