[jira] [Updated] (TS-3699) TLS 64GB transfer fails with AES GCM cipher

2016-04-11 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3699?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3699: -- Fix Version/s: (was: 6.2.0) 7.0.0 > TLS 64GB transfer fails with AES GCM cipher >

[jira] [Updated] (TS-3559) ATS should support client side TLS session ticket caching/use.

2016-04-11 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3559?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3559: -- Fix Version/s: (was: 6.2.0) 7.0.0 > ATS should support client side TLS session

[jira] [Commented] (TS-3559) ATS should support client side TLS session ticket caching/use.

2016-04-11 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3559?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15235198#comment-15235198 ] Dave Thompson commented on TS-3559: --- Pushing out fix version. > ATS should support client side TLS session

[jira] [Commented] (TS-3699) TLS 64GB transfer fails with AES GCM cipher

2016-04-11 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3699?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15235191#comment-15235191 ] Dave Thompson commented on TS-3699: --- Key rescheduling recommendations are still being discussed in IETF

[jira] [Created] (TS-4247) Should no longer allow SSLv2 configuration

2016-03-01 Thread Dave Thompson (JIRA)
Dave Thompson created TS-4247: - Summary: Should no longer allow SSLv2 configuration Key: TS-4247 URL: https://issues.apache.org/jira/browse/TS-4247 Project: Traffic Server Issue Type: Bug

[jira] [Commented] (TS-3699) TLS 64GB transfer fails with AES GCM cipher

2016-01-05 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3699?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15083752#comment-15083752 ] Dave Thompson commented on TS-3699: --- Status Note: at IETF94 TLS working group (Nov 2015), ciphers re-keying

[jira] [Commented] (TS-3277) Core durring ssl handshake

2015-09-10 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3277?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14739754#comment-14739754 ] Dave Thompson commented on TS-3277: --- Yes, there is a way to check the setting of the crypto locking

[jira] [Issue Comment Deleted] (TS-3277) Core durring ssl handshake

2015-09-08 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3277?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3277: -- Comment: was deleted (was: A quick status update on the SHA1_Update() crash trace (NOT necessarily the

[jira] [Commented] (TS-3277) Core durring ssl handshake

2015-09-08 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3277?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14735124#comment-14735124 ] Dave Thompson commented on TS-3277: --- A quick status update: Core traces showing crash in SHA1_Update()

[jira] [Comment Edited] (TS-3277) Core durring ssl handshake

2015-09-08 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3277?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14735124#comment-14735124 ] Dave Thompson edited comment on TS-3277 at 9/8/15 4:43 PM: --- A quick status update

[jira] [Commented] (TS-3277) Core durring ssl handshake

2015-09-08 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3277?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14735136#comment-14735136 ] Dave Thompson commented on TS-3277: --- A quick status update on the SHA1_Update() crash trace in original

[jira] [Commented] (TS-3277) Core durring ssl handshake

2015-09-08 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3277?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14735293#comment-14735293 ] Dave Thompson commented on TS-3277: --- OpenSSL (actually cryptolib) has a static function pointer which

[jira] [Updated] (TS-3559) ATS should support client side TLS session ticket caching/use.

2015-07-09 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3559?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3559: -- Labels: Yahoo (was: ) ATS should support client side TLS session ticket caching/use.

[jira] [Updated] (TS-3699) TLS 64GB transfer fails with AES GCM cipher

2015-07-09 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3699?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3699: -- Labels: Yahoo (was: ) TLS 64GB transfer fails with AES GCM cipher

[jira] [Commented] (TS-3277) Core durring ssl handshake

2015-07-09 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3277?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14621044#comment-14621044 ] Dave Thompson commented on TS-3277: --- Observation, a commonality between several of these

[jira] [Commented] (TS-3559) ATS should support client side TLS session ticket caching/use.

2015-06-25 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3559?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14601873#comment-14601873 ] Dave Thompson commented on TS-3559: --- Code pushed, pull request posted here:

[jira] [Closed] (TS-3716) Add TLS-version control on origin server to config

2015-06-25 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3716?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson closed TS-3716. - Resolution: Invalid Closing issue for reasons mentioned above, i.e. ATS already had config for client side

[jira] [Commented] (TS-3716) Add TLS-version control on origin server to config

2015-06-24 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3716?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14600209#comment-14600209 ] Dave Thompson commented on TS-3716: --- We already have configs:

[jira] [Updated] (TS-3716) Add TLS-version control on origin server to config

2015-06-24 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3716?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3716: -- Summary: Add TLS-version control on origin server to config (was: ATS client side TLS version should be

[jira] [Created] (TS-3716) ATS client side TLS version should be configurable

2015-06-24 Thread Dave Thompson (JIRA)
Dave Thompson created TS-3716: - Summary: ATS client side TLS version should be configurable Key: TS-3716 URL: https://issues.apache.org/jira/browse/TS-3716 Project: Traffic Server Issue Type:

[jira] [Commented] (TS-3559) ATS should support client side TLS session ticket caching/use.

2015-06-24 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3559?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14599662#comment-14599662 ] Dave Thompson commented on TS-3559: --- session ticket cache support on ATS pushed unit and

[jira] [Created] (TS-3699) TLS 64GB transfer fails with AES GCM cipher

2015-06-17 Thread Dave Thompson (JIRA)
Dave Thompson created TS-3699: - Summary: TLS 64GB transfer fails with AES GCM cipher Key: TS-3699 URL: https://issues.apache.org/jira/browse/TS-3699 Project: Traffic Server Issue Type: Bug

[jira] [Commented] (TS-3136) Change default TLS cipher suites

2015-06-16 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3136?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14588253#comment-14588253 ] Dave Thompson commented on TS-3136: --- I did some performance tests a while back using ATS.

[jira] [Commented] (TS-3136) Change default TLS cipher suites

2015-06-16 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3136?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14588316#comment-14588316 ] Dave Thompson commented on TS-3136: --- Doh, I meant RC4 as in RC4_SHA, That would be a

[jira] [Commented] (TS-3136) Change default TLS cipher suites

2015-06-12 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3136?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14583847#comment-14583847 ] Dave Thompson commented on TS-3136: --- In march, I did a survey of ciphers selected by

[jira] [Created] (TS-3570) Need to implement TLS server side Session ID and Session Ticket expiration

2015-04-29 Thread Dave Thompson (JIRA)
Dave Thompson created TS-3570: - Summary: Need to implement TLS server side Session ID and Session Ticket expiration Key: TS-3570 URL: https://issues.apache.org/jira/browse/TS-3570 Project: Traffic

[jira] [Commented] (TS-3570) Need to implement TLS server side Session ID and Session Ticket expiration

2015-04-29 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3570?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14520198#comment-14520198 ] Dave Thompson commented on TS-3570: --- I didn't see expiration time check done at ATS level,

[jira] [Work started] (TS-3570) Need to implement TLS server side Session ID and Session Ticket expiration

2015-04-29 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3570?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Work on TS-3570 started by Dave Thompson. - Need to implement TLS server side Session ID and Session Ticket expiration

[jira] [Commented] (TS-3570) Need to implement TLS server side Session ID and Session Ticket expiration

2015-04-29 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3570?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=14520176#comment-14520176 ] Dave Thompson commented on TS-3570: --- Ok, thanks Leif. good to know. Need to implement

[jira] [Closed] (TS-3570) Need to implement TLS server side Session ID and Session Ticket expiration

2015-04-29 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3570?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson closed TS-3570. - Resolution: Invalid Need to implement TLS server side Session ID and Session Ticket expiration

[jira] [Updated] (TS-3538) ATS Should perform validity checks on certificate prior to serving

2015-04-27 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3538?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3538: -- Attachment: diff-ts-3538 Attaching code diff.This code change to iocore/net/SSLUtils.cc will check

[jira] [Created] (TS-3559) ATS should support client side TLS session ticket caching/use.

2015-04-27 Thread Dave Thompson (JIRA)
Dave Thompson created TS-3559: - Summary: ATS should support client side TLS session ticket caching/use. Key: TS-3559 URL: https://issues.apache.org/jira/browse/TS-3559 Project: Traffic Server

[jira] [Updated] (TS-3538) ATS Should perform validity checks on certificate prior to serving

2015-04-27 Thread Dave Thompson (JIRA)
[ https://issues.apache.org/jira/browse/TS-3538?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dave Thompson updated TS-3538: -- Attachment: diff-ts-3538-v2 Ok. Attaching diff, with set lookup-isValid to false. ATS Should perform

[jira] [Created] (TS-3538) ATS Should perform validity checks on certificate prior to serving

2015-04-21 Thread Dave Thompson (JIRA)
Dave Thompson created TS-3538: - Summary: ATS Should perform validity checks on certificate prior to serving Key: TS-3538 URL: https://issues.apache.org/jira/browse/TS-3538 Project: Traffic Server