[
https://issues.jboss.org/browse/WFLY-3451?page=com.atlassian.jira.plugin....
]
Darran Lofthouse commented on WFLY-3451:
----------------------------------------
If you are a supported customer please open a support case through the customer portal: -
https://access.redhat.com/home
Jira is the community side of issue management, I will move this issue under a set of
tasks where we are enhancing the SSL configuration for WildFly but a support case will be
required to consider the options for EAP.
disabling CBC mode ciphers
--------------------------
Key: WFLY-3451
URL:
https://issues.jboss.org/browse/WFLY-3451
Project: WildFly
Issue Type: Support Request
Security Level: Public(Everyone can see)
Affects Versions: JBoss AS7 7.1.1.Final
Reporter: Aleksandr Voloschuk
Assignee: Darran Lofthouse
Priority: Critical
encountered such a problem:
management of information security vulnerability found on a production environment,
namely:
SSLv3.0/TLSv1.0 Protocol Weak CBC Mode Vulnerability port 8443/tcp over SSL
RC4-SHA ECDHE-RSA-DES-CBC3-SHA SSLv3
they offer a solution:
This attack was identified in 2004 and later revisions of TLS protocol which contain a
fix for this. If possible, upgrade to TLSv1.1 or TLSv1.2. If
upgrading to TLSv1.1 or TLSv1.2 is not possible, then disabling CBC mode ciphers will
remove the vulnerability. Setting your SSL server to prioritize RC4 ciphers mitigates this
vulnerability.
as TLS upgrade we can not, it remains disabling CBC mode ciphers
our platform is jboss-eap-6.1
--
This message was sent by Atlassian JIRA
(v6.2.3#6260)