[ 
https://issues.apache.org/jira/browse/DIRAPI-474?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Emmanuel Lécharny updated DIRAPI-474:
-------------------------------------
    Description: 
A client on an old *JDK* (*TLSv1* still enabled platform-wide) connects with 
_useSsl_.
A legacy or attacker-run server negotiates *TLSv1.0* with *CBC* suites.
The handshake succeeds on a deprecated protocol it could not have negotiated 
with *JDK* defaults, exposing the tunnel to protocol-level weaknesses.

> Deprecated TLSv1 and TLSv1.1 enabled by default for LDAPS/StartTLS
> ------------------------------------------------------------------
>
>                 Key: DIRAPI-474
>                 URL: https://issues.apache.org/jira/browse/DIRAPI-474
>             Project: Directory Client API
>          Issue Type: Bug
>    Affects Versions: 2.1.8
>            Reporter: Emmanuel Lécharny
>            Priority: Major
>             Fix For: 2.1.9
>
>
> A client on an old *JDK* (*TLSv1* still enabled platform-wide) connects with 
> _useSsl_.
> A legacy or attacker-run server negotiates *TLSv1.0* with *CBC* suites.
> The handshake succeeds on a deprecated protocol it could not have negotiated 
> with *JDK* defaults, exposing the tunnel to protocol-level weaknesses.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to