Java crypto roadmap

Cantor, Scott cantor.2 at osu.edu
Wed Oct 16 10:37:04 EDT 2019


On 10/16/19, 10:34 AM, "dev on behalf of Ian Young" <dev-bounces at shibboleth.net on behalf of ian at iay.org.uk> wrote:

> * TLS 1.0 and TLS 1.1 being *disabled* in all versions of Java from Java 7 onwards, second half of 2020. This is new and
> will presumably affect existing deployments if they take the relevant Java update (which I have to assume a lot of people
> will).

As in "removed" or just a default policy rule that can be overridden to turn them back on?

I broke a bunch of Red Hat <mumble> systems by turning off TLS 1.1 on my Jetty servers where I host my metadata locally so this would be a big deal if not revocable.

-- Scott




More information about the dev mailing list