Hi Jason,

I did have a chat to one of our server guys and he suggested similar -
we're running on tomcat and he said it would take about 10 minutes to
change the config.  Shame that I don't currently have access to the
mid-tier in order to make the requisite changes.

Regards

Dave

On 7 July 2015 at 18:57, Jason Miller <[email protected]> wrote:

> **
> This sounds similar to when Firefox, Chrome and later IE11 start blocking
> SSLv3. I am assuming your are using SSL to access Mid Tier?
>
> It is likely not MT specifically but the web server configuration. Are you
> running just Tomcat or do you have Apache httpd in front of Tomcat? Either
> way one of those will have a section where you configure the allowed
> ciphers.
>
> Here is a page that has some more info: https://weakdh.org/   and
> specifically     https://weakdh.org/sysadmin.html     for additional info.
>
> Keeping on top of the allowed protocols and ciphers is a bit of an art and
> seems to be turning into full time job. We can't just set them and forget
> them (as many of us have done int he past). Browsers are starting to
> protect users by putting in these kind of block (because so many server
> admins were setting and forgetting or just understand enough to make the
> server work). Unfortunately it just about takes a scientist to figure out
> much of this SSL stuff (or at least a lot of Googling).
>
> Jason
>
>
>
> On Tue, Jul 7, 2015 at 4:24 AM, Dave Barber <[email protected]>
> wrote:
>
>> **
>> Our ITSM 8.1 servers are running on Ubuntu, we have a patched 8.1
>> install, along with the full ITSM suite.  All the mid-tier servers are also
>> running on Ubuntu as well.
>>
>> This week, when accessing via Firefox (31.8, ESR, updated last week iirc)
>> I receive an error regarding Diffie-Hellman - its basically the recently
>> reported "logjam" vulnerability.  Our IE build is considerably older and
>> virtually goes straight in (it isn't "aware" of the issue).
>>
>> My server knowledge is basic, any suggestions what is needed to fix
>> this?  We have potential workarounds, but ideally a fix ....
>>
>> Regards
>>
>> Dave
>> _ARSlist: "Where the Answers Are" and have been for 20 years_
>
>
> _ARSlist: "Where the Answers Are" and have been for 20 years_

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

Reply via email to