[
https://issues.apache.org/jira/browse/CXF-8265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andriy Redko resolved CXF-8265.
-------------------------------
Resolution: Fixed
> [JDK14] Accommodate SSLv3 deprecation
> -------------------------------------
>
> Key: CXF-8265
> URL: https://issues.apache.org/jira/browse/CXF-8265
> Project: CXF
> Issue Type: Task
> Reporter: Andriy Redko
> Assignee: Andriy Redko
> Priority: Major
> Fix For: 3.4.0
>
>
> Since JDK14, SSLv3 is no longer supported and is removed from SSLContext
> ([https://github.com/openjdk/jdk/blob/jdk-14-ga/src/java.base/share/classes/sun/security/ssl/SSLContextImpl.java#L603|https://github.com/openjdk/jdk/blob/jdk-14-ga/src/java.base/share/classes/sun/security/ssl/SSLContextImpl.java#L603),]
> vs
> [https://github.com/openjdk/jdk/blob/jdk-13-ga/src/java.base/share/classes/sun/security/ssl/SSLContextImpl.java#L615),]
> TLSv1.0 is the minimal supported version.
> To allow SSLv3, the connections, the client / server have to create a custom
> SSL context (fe "SSL") and control the protocols using JDK's
> jdk.tls.server.protocols and jdk.tls.client.protocols properties, fe:
> -Djdk.tls.server.protocols=SSLv3,TLSv1
> -Djdk.tls.client.protocols=SSLv3,TLSv1
--
This message was sent by Atlassian Jira
(v8.3.4#803005)