Repository: cxf Updated Branches: refs/heads/3.0.x-fixes 11725278a -> a7f600ce9
Disable SSLv2Hello unless server protocol is SSLv3 Project: http://git-wip-us.apache.org/repos/asf/cxf/repo Commit: http://git-wip-us.apache.org/repos/asf/cxf/commit/a7f600ce Tree: http://git-wip-us.apache.org/repos/asf/cxf/tree/a7f600ce Diff: http://git-wip-us.apache.org/repos/asf/cxf/diff/a7f600ce Branch: refs/heads/3.0.x-fixes Commit: a7f600ce96c8300605ba7a044dd4ba4fa6c5b32f Parents: 1172527 Author: Colm O hEigeartaigh <[email protected]> Authored: Thu Nov 6 10:20:11 2014 +0000 Committer: Colm O hEigeartaigh <[email protected]> Committed: Thu Nov 6 10:20:11 2014 +0000 ---------------------------------------------------------------------- .../cxf/transport/https_jetty/CXFJettySslSocketConnector.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) ---------------------------------------------------------------------- http://git-wip-us.apache.org/repos/asf/cxf/blob/a7f600ce/rt/transports/http-jetty/src/main/java/org/apache/cxf/transport/https_jetty/CXFJettySslSocketConnector.java ---------------------------------------------------------------------- diff --git a/rt/transports/http-jetty/src/main/java/org/apache/cxf/transport/https_jetty/CXFJettySslSocketConnector.java b/rt/transports/http-jetty/src/main/java/org/apache/cxf/transport/https_jetty/CXFJettySslSocketConnector.java index 072c7d0..619850d 100644 --- a/rt/transports/http-jetty/src/main/java/org/apache/cxf/transport/https_jetty/CXFJettySslSocketConnector.java +++ b/rt/transports/http-jetty/src/main/java/org/apache/cxf/transport/https_jetty/CXFJettySslSocketConnector.java @@ -121,10 +121,11 @@ public class CXFJettySslSocketConnector extends SslSelectChannelConnector { ? "TLS" : getCxfSslContextFactory().getProtocol(); - // Exclude SSLv3 by default unless the protocol is given as SSLv3 + // Exclude SSLv3 + SSLv2Hello by default unless the protocol is given as SSLv3 if (!"SSLv3".equals(proto) && (excludeProtocols == null || excludeProtocols.isEmpty())) { getSslContextFactory().addExcludeProtocols("SSLv3"); + getSslContextFactory().addExcludeProtocols("SSLv2Hello"); } else if (excludeProtocols != null) { for (String p : excludeProtocols) { getSslContextFactory().addExcludeProtocols(p);
