New denial of service tool knocks out encrypting servers

Eric Griffith egriffith92 at
Wed Oct 26 02:58:33 UTC 2011

I link the article to make sure everyone see's it; but also to frame a
question. The "Fix" seems to be to simply disable SSL-Renegotiation so
that its not hammered over and over. The question: How do you disable
SSL Renegotiation on Nginx? I tried googling "Nginx Disable SSL
Renegotiation" but all that came back was patches to add the ability
TO disable it in Nginx, no actual config option. Anyone know?

