Notable Jetty 9.3.7 Change

Cantor, Scott cantor.2 at osu.edu
Thu Mar 17 11:40:00 EDT 2016


> Bottom line: the Jetty project appears to favor security over interoperability
> and deployers should explicitly configure both include/excludeProtocols and
> include/excludeCipherSuites in jetty-ssl-context.xml to ensure a stable
> configuration under upgrades.

Originally I thought you mean 9.3.8. There are a couple of things in their list for that that I found highly suspicious also, so I would expect further disruption.

*	[Enhancement] New RFC2616 HTTP 1.x Parser Compliance Mode
*	[Update] SSLContextFactory defaults updated to suit new Google Chrome requirements

-- Scott



More information about the users mailing list