Re: OpenSSL, Cipher-Suites, and Tomcat standalone vs. native vs. Tomcat behind apache-httpd

2015-05-21 Thread Konstantin Kolinko
2015-05-21 2:22 GMT+03:00 Glen Peterson g...@organicdesign.org: OS: Linux i386 2.6.18-404.el5 Java: Oracle Corporation Java HotSpot(TM) Server VM 1.8.0_45 Tomcat: Apache Tomcat/8.0.21 On Wed, May 20, 2015 at 7:12 PM, Glen Peterson g...@organicdesign.org wrote: I've been using Tomcat as a

Re: OpenSSL, Cipher-Suites, and Tomcat standalone vs. native vs. Tomcat behind apache-httpd

2015-05-21 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Konstantin, On 5/21/15 8:35 AM, Konstantin Kolinko wrote: 2015-05-21 2:22 GMT+03:00 Glen Peterson g...@organicdesign.org: OS: Linux i386 2.6.18-404.el5 Java: Oracle Corporation Java HotSpot(TM) Server VM 1.8.0_45 Tomcat: Apache Tomcat/8.0.21

Re: OpenSSL, Cipher-Suites, and Tomcat standalone vs. native vs. Tomcat behind apache-httpd

2015-05-20 Thread Glen Peterson
OS: Linux i386 2.6.18-404.el5 Java: Oracle Corporation Java HotSpot(TM) Server VM 1.8.0_45 Tomcat: Apache Tomcat/8.0.21 On Wed, May 20, 2015 at 7:12 PM, Glen Peterson g...@organicdesign.org wrote: I've been using Tomcat as a stand-alone web server for years. Last year, I started testing my

OpenSSL, Cipher-Suites, and Tomcat standalone vs. native vs. Tomcat behind apache-httpd

2015-05-20 Thread Glen Peterson
I've been using Tomcat as a stand-alone web server for years. Last year, I started testing my site here: https://www.ssllabs.com/ssltest I notice that there are only 3 fully secure cipher-suites left (there were 6 left 2 months ago). Also, I only get an A, not an A+ due to TLS_­FALLBACK_­SCSV