tweaking security of IdP deployment

Cantor, Scott cantor.2 at osu.edu
Fri Dec 12 16:24:52 EST 2014


On 12/12/14, 8:32 PM, "IAM David Bantz" <dabantz at alaska.edu> wrote:



>My IdP is running in tomcat 6.0.16-0 [updated SSL libraries 
>mod_ssl.x86_64 1:2.2.3-91.el5,  openssl.i686  0.9.8e-31.el5_11, 
>openssl.x86_64  0.9.8e-31.el5_11 and java-sun.x86_64 
>1.6.0.45-1jpp.1.el5_9 ].

OpenSSL isn't relevant, and Java 6 is EOL. So you'd start by moving to 
Java 7.

>Removing older ciphers this way is effective (they don't show up in SSL 
>Labs test), but SSL Labs test still indicates support for SSL 3 and not 
>TLS 1.2 (nor 1.1 for that matter).

I would ask Tomcat's list how to disable SSLv3 for certain if that isn't 
doing it.

-- Scott



More information about the users mailing list