How can I disable less secure encryption methods and use only TLS within the ivy engine?

Thanks for your feedback, Sven

27.07.2016

Only TLS should be enabled by default anyway. See System Property "WebServer.HTTPS.SslProtocol", it is set to TLS by default.

See System Properties in the Engine Guide to learn more about it.


03.08.2016

Hi there

is there a possibility to change the enabled ssl protocols?

To disable SSL v3, and enable all TLS protocols on JSSE connectors add the following attributes to your HTTPS connector configuration in server.xml:

sslProtocol="TLS" sslEnabledProtocols="TLSv1.2,TLSv1.1,TLSv1"

Information here: https://wiki.apache.org/tomcat/Security/POODLE



13.09.2016

Asked: 27.07.2016

Last updated: 13.09.2016