X509 authn under Jetty

Cantor, Scott cantor.2 at osu.edu
Tue Aug 23 13:12:00 EDT 2016


On 8/23/16 12:09 PM, Ian Bobbitt wrote:
> 
> If you're talking about what I think you're talking about (CVE-2009-3555), it's been fixed in the JRE for quite a while
> (since 6u22 <http://www.oracle.com/technetwork/java/javase/documentation/tlsreadme2-176330.html>)

That's really just the tip of the iceberg. My understanding is that
increasingly the default is "turn off renegotiation" full stop.

I think the problem is that alot of TLS behavior is broken or behaves
incorrectly when it's allowed, and over time that leads to more and more
security problems. It's a pre-emptive move now to just get rid of it.

That's all my very limited understanding of matters.

-- Scott


More information about the users mailing list