RE: SSL/TLS and ciphers vulnerability

2016-07-15 Thread Robert Sulliman
ers@tomcat.apache.org> Subject: Re: SSL/TLS and ciphers vulnerability -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 All, On 7/14/16 9:22 PM, Christopher Schultz wrote: > Mark, > > On 7/14/16 4:14 PM, Mark Thomas wrote: >> On 14/07/2016 19:36, uzair rashid wrote: >>> Jeffrey, >

Re: SSL/TLS and ciphers vulnerability

2016-07-15 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 All, On 7/14/16 9:22 PM, Christopher Schultz wrote: > Mark, > > On 7/14/16 4:14 PM, Mark Thomas wrote: >> On 14/07/2016 19:36, uzair rashid wrote: >>> Jeffrey, >>> >>> Working for a corporation that has strict ssl and security >>> requirements..

Re: SSL/TLS and ciphers vulnerability

2016-07-14 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mark, On 7/14/16 4:14 PM, Mark Thomas wrote: > On 14/07/2016 19:36, uzair rashid wrote: >> Jeffrey, >> >> Working for a corporation that has strict ssl and security >> requirements.. There is no way to use the tools you suggested, >> since the

Re: SSL/TLS and ciphers vulnerability

2016-07-14 Thread Mark Thomas
On 14/07/2016 19:36, uzair rashid wrote: > Jeffrey, > > Working for a corporation that has strict ssl and security requirements.. > There is no way to use the tools you suggested, since the tomcat URLs are > not exposed. That doesn't stop you setting up a stand-alone test instance using the same

Re: SSL/TLS and ciphers vulnerability

2016-07-14 Thread uzair rashid
Jeffrey, Working for a corporation that has strict ssl and security requirements.. There is no way to use the tools you suggested, since the tomcat URLs are not exposed. On Thu, Jul 14, 2016 at 8:41 AM, Jeffrey Janner wrote: > Hi folks, > > I've been off the list

SSL/TLS and ciphers vulnerability

2016-07-14 Thread Jeffrey Janner
Hi folks, I've been off the list for a bit, getting ducks in a row here and everything. I noticed a number of posts about SSL & TLS security settings lately and I wanted to point out that maintaining your SSL configurations is an on-going processes. New exploits are discovered and released