More info: - https://poodle.io/ - https://community.rapid7.com/community/infosec/blog/2014/10/14/poodle-unleashed-understanding-the-ssl-30-vulnerability SSLv3 support should be removed by default. If someone really need it it could use it by specifying a custom ssl_protocol argument.