X509 configuration in Jetty
Cantor, Scott
cantor.2 at osu.edu
Fri Dec 15 11:11:38 EST 2017
On 12/15/17, 10:35 AM, "users on behalf of Ian Bobbitt" <users-bounces at shibboleth.net on behalf of ibobbitt at globalnoc.iu.edu> wrote:
> My production IdPs are behind an Apache proxy for other reasons, so I terminated the client certificate there (which can
> renegotiate depending on path)
Do you happen to know or have a concise summary of exactly what the state of renegotiation is in TLS? I really have lost track after the millionth advisory that it's unsafe, TLS extension to fix it, flags in clients to turn it off, etc.
-- Scott
More information about the users
mailing list