tweaking security of IdP deployment
Kevin Foote
kpfoote at uoregon.edu
Fri Dec 12 15:39:44 EST 2014
> On Dec 12, 2014, at 12:32 PM, IAM David Bantz <dabantz at alaska.edu> wrote:
>
> Removing older ciphers this way is effective (they don't show up in SSL Labs test), but SSL Labs test still indicates support for SSL 3 and not TLS 1.2 (nor 1.1 for that matter).
>
> While not strictly a Shibboleth issue, there must be many of you running a similar deployment in tomcat who have addressed this issue. Help!
Hi David,
Just verifying that you are not fronting with Apache and then bumping to Tomcat.
If your fronting w/ Apache then all you have to add is
SSLProtocol TLSv1
--------
thanks
kevin.foote
More information about the users
mailing list