Hi Jason, I did have a chat to one of our server guys and he suggested similar - we're running on tomcat and he said it would take about 10 minutes to change the config. Shame that I don't currently have access to the mid-tier in order to make the requisite changes.
Regards Dave On 7 July 2015 at 18:57, Jason Miller <[email protected]> wrote: > ** > This sounds similar to when Firefox, Chrome and later IE11 start blocking > SSLv3. I am assuming your are using SSL to access Mid Tier? > > It is likely not MT specifically but the web server configuration. Are you > running just Tomcat or do you have Apache httpd in front of Tomcat? Either > way one of those will have a section where you configure the allowed > ciphers. > > Here is a page that has some more info: https://weakdh.org/ and > specifically https://weakdh.org/sysadmin.html for additional info. > > Keeping on top of the allowed protocols and ciphers is a bit of an art and > seems to be turning into full time job. We can't just set them and forget > them (as many of us have done int he past). Browsers are starting to > protect users by putting in these kind of block (because so many server > admins were setting and forgetting or just understand enough to make the > server work). Unfortunately it just about takes a scientist to figure out > much of this SSL stuff (or at least a lot of Googling). > > Jason > > > > On Tue, Jul 7, 2015 at 4:24 AM, Dave Barber <[email protected]> > wrote: > >> ** >> Our ITSM 8.1 servers are running on Ubuntu, we have a patched 8.1 >> install, along with the full ITSM suite. All the mid-tier servers are also >> running on Ubuntu as well. >> >> This week, when accessing via Firefox (31.8, ESR, updated last week iirc) >> I receive an error regarding Diffie-Hellman - its basically the recently >> reported "logjam" vulnerability. Our IE build is considerably older and >> virtually goes straight in (it isn't "aware" of the issue). >> >> My server knowledge is basic, any suggestions what is needed to fix >> this? We have potential workarounds, but ideally a fix .... >> >> Regards >> >> Dave >> _ARSlist: "Where the Answers Are" and have been for 20 years_ > > > _ARSlist: "Where the Answers Are" and have been for 20 years_ _______________________________________________________________________________ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org "Where the Answers Are, and have been for 20 years"

