[ 
https://issues.apache.org/jira/browse/DIRAPI-474?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120601#comment-18120601
 ] 

Emmanuel Lécharny commented on DIRAPI-474:
------------------------------------------

Found by Claude

> Deprecated TLSv1 and TLSv1.1 enabled by default for LDAPS/StartTLS
> ------------------------------------------------------------------
>
>                 Key: DIRAPI-474
>                 URL: https://issues.apache.org/jira/browse/DIRAPI-474
>             Project: Directory Client API
>          Issue Type: Bug
>    Affects Versions: 2.1.8
>            Reporter: Emmanuel Lécharny
>            Priority: Minor
>             Fix For: 2.1.9
>
>
> A client on an old *JDK* (*TLSv1* still enabled platform-wide) connects with 
> _useSsl_.
> A legacy or attacker-run server negotiates *TLSv1.0* with *CBC* suites.
> The handshake succeeds on a deprecated protocol it could not have negotiated 
> with *JDK* defaults, exposing the tunnel to protocol-level weaknesses.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to