tweaking security of IdP deployment
Cantor, Scott
cantor.2 at osu.edu
Sat Dec 13 16:08:53 EST 2014
On 12/12/14, 9:24 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>>Removing older ciphers this way is effective (they don't show up in SSL
>>Labs test), but SSL Labs test still indicates support for SSL 3 and not
>>TLS 1.2 (nor 1.1 for that matter).
>
>I would ask Tomcat's list how to disable SSLv3 for certain if that isn't
>doing it.
FYI, the latest versions of Tomcat 6, 7, and 8 all disable SSLv3 by
default now.
-- Scott
More information about the users
mailing list