[
https://issues.apache.org/jira/browse/FELIX-4674?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Felix Meschberger resolved FELIX-4674.
--------------------------------------
Resolution: Fixed
Fix Version/s: http-2.3.2
Thanks for providing the patch. I have applied it somewhat extended in Rev.
1633120
The extension is to additionally support the included protocols for
whitelisting and to add some more explanations to the property descriptions.
> Allow inclusion/exclusion of protocols in SSL connector
> -------------------------------------------------------
>
> Key: FELIX-4674
> URL: https://issues.apache.org/jira/browse/FELIX-4674
> Project: Felix
> Issue Type: Improvement
> Components: HTTP Service
> Affects Versions: http-2.3.0
> Reporter: Dominique Pfister
> Assignee: Felix Meschberger
> Fix For: http-2.3.2
>
> Attachments: patch.txt
>
>
> With the recent security attack discovered called "POODLE" [1], it would be
> great to make the set of SSL protocols Jetty accepts configurable through
> OSGI. I suggest to introduce a string array property containing the list of
> protocols to disable, e.g. [ "SSLv3" ].
> [1] https://zmap.io/sslv3/
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)