[ 
https://issues.apache.org/jira/browse/DIRSERVER-2020?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14218543#comment-14218543
 ] 

Emmanuel Lecharny commented on DIRSERVER-2020:
----------------------------------------------

Thanks Chris. This is probably right, we are most certainly safe.

OTOH, SSLv3 should have died a decade ago, and it didn't thanks to M$ crappy 
browsers. So disabling SSLv3 from the server should not harm, and it's not 
really a costly modification.

> Poodle remediation for ApacheDS 2.X
> -----------------------------------
>
>                 Key: DIRSERVER-2020
>                 URL: https://issues.apache.org/jira/browse/DIRSERVER-2020
>             Project: Directory ApacheDS
>          Issue Type: Task
>          Components: ldap
>    Affects Versions: 2.0.0-M10
>         Environment: Production
>            Reporter: RakeshAcharya
>            Priority: Critical
>              Labels: patch
>
> How do we disable SSlv3 protocol for apache DS 2.X ?
> As part of poodle remediation we need to disable SSL v3 ASAP in production 
> boxes as the scan showed its vulnerable.
> I cant find any configuration pertaining to the same which I could change .



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to