[ https://issues.apache.org/jira/browse/QPID-6160?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14174336#comment-14174336 ]
Steve Huston commented on QPID-6160: ------------------------------------ Note that in case Windows users are confused about this issue, there are no code changes required. Restriction of SSLv2 and SSLv3 is done via registry settings as described at: http://support2.microsoft.com/default.aspx?scid=kb;EN-US;245030 > CLONE - [CPP Broker] [CPP Client] Disable SSLv3 support > ------------------------------------------------------- > > Key: QPID-6160 > URL: https://issues.apache.org/jira/browse/QPID-6160 > Project: Qpid > Issue Type: Bug > Components: Java Broker, Java Client > Reporter: Ken Giusti > Assignee: Ken Giusti > Fix For: 0.31 > > > SSLv3 is vulnerable to CVE-2014-3566, and will not fixed. > Wherever a seure connection is established we should ensure that SSLv3 is not > in the supported protocols. -- This message was sent by Atlassian JIRA (v6.3.4#6332) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@qpid.apache.org For additional commands, e-mail: dev-h...@qpid.apache.org