Bill Blough created AXIS2C-1700: ----------------------------------- Summary: Enable SSL/TLS peer name validation by default Key: AXIS2C-1700 URL: https://issues.apache.org/jira/browse/AXIS2C-1700 Project: Axis2-C Issue Type: Bug Components: transport/http Reporter: Bill Blough
I've looked through the source code and cannot find any peer hostname validation code. It appears to me that Axis2/c is vulnerable to the problems discussed in this paper: http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf Have I overlooked the TLS / SSL peer name validation? Thanks -- This message was sent by Atlassian Jira (v8.3.2#803003) --------------------------------------------------------------------- To unsubscribe, e-mail: c-dev-unsubscr...@axis.apache.org For additional commands, e-mail: c-dev-h...@axis.apache.org