[
https://issues.apache.org/jira/browse/QPID-6160?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14174336#comment-14174336
]
Steve Huston commented on QPID-6160:
------------------------------------
Note that in case Windows users are confused about this issue, there are no
code changes required. Restriction of SSLv2 and SSLv3 is done via registry
settings as described at:
http://support2.microsoft.com/default.aspx?scid=kb;EN-US;245030
> CLONE - [CPP Broker] [CPP Client] Disable SSLv3 support
> -------------------------------------------------------
>
> Key: QPID-6160
> URL: https://issues.apache.org/jira/browse/QPID-6160
> Project: Qpid
> Issue Type: Bug
> Components: Java Broker, Java Client
> Reporter: Ken Giusti
> Assignee: Ken Giusti
> Fix For: 0.31
>
>
> SSLv3 is vulnerable to CVE-2014-3566, and will not fixed.
> Wherever a seure connection is established we should ensure that SSLv3 is not
> in the supported protocols.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]