This sounds similar to when Firefox, Chrome and later IE11 start blocking
SSLv3. I am assuming your are using SSL to access Mid Tier?

It is likely not MT specifically but the web server configuration. Are you
running just Tomcat or do you have Apache httpd in front of Tomcat? Either
way one of those will have a section where you configure the allowed
ciphers.

Here is a page that has some more info: https://weakdh.org/   and
specifically     https://weakdh.org/sysadmin.html     for additional info.

Keeping on top of the allowed protocols and ciphers is a bit of an art and
seems to be turning into full time job. We can't just set them and forget
them (as many of us have done int he past). Browsers are starting to
protect users by putting in these kind of block (because so many server
admins were setting and forgetting or just understand enough to make the
server work). Unfortunately it just about takes a scientist to figure out
much of this SSL stuff (or at least a lot of Googling).

Jason



On Tue, Jul 7, 2015 at 4:24 AM, Dave Barber <[email protected]> wrote:

> **
> Our ITSM 8.1 servers are running on Ubuntu, we have a patched 8.1 install,
> along with the full ITSM suite.  All the mid-tier servers are also running
> on Ubuntu as well.
>
> This week, when accessing via Firefox (31.8, ESR, updated last week iirc)
> I receive an error regarding Diffie-Hellman - its basically the recently
> reported "logjam" vulnerability.  Our IE build is considerably older and
> virtually goes straight in (it isn't "aware" of the issue).
>
> My server knowledge is basic, any suggestions what is needed to fix this?
> We have potential workarounds, but ideally a fix ....
>
> Regards
>
> Dave
> _ARSlist: "Where the Answers Are" and have been for 20 years_

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

Reply via email to