tweaking security of IdP deployment

Kevin Foote kpfoote at uoregon.edu
Fri Dec 12 15:39:44 EST 2014



> On Dec 12, 2014, at 12:32 PM, IAM David Bantz <dabantz at alaska.edu> wrote:
> 
> Removing older ciphers this way is effective (they don't show up in SSL Labs test), but SSL Labs test still indicates support for SSL 3 and not TLS 1.2 (nor 1.1 for that matter).
> 
> While not strictly a Shibboleth issue, there must be many of you running a similar deployment in tomcat who have addressed this issue.  Help!


Hi David, 

Just verifying that you are not fronting with Apache and then bumping to Tomcat. 

If your fronting w/ Apache then all you have to add is 

SSLProtocol TLSv1

--------
thanks
 kevin.foote



More information about the users mailing list