John Zhuge created HDFS-11816:
---------------------------------

             Summary: Update ciphers list for HttpFS
                 Key: HDFS-11816
                 URL: https://issues.apache.org/jira/browse/HDFS-11816
             Project: Hadoop HDFS
          Issue Type: Improvement
          Components: httpfs, security
    Affects Versions: 2.9.0
            Reporter: John Zhuge
            Assignee: John Zhuge
            Priority: Minor


In Oracle Linux 6.8 configurations, the curl command cannot connect to certain 
CDH services that run on Apache Tomcat when the cluster has been configured for 
TLS/SSL. Specifically, HttpFS, KMS, Oozie, and Solr services reject connection 
attempts because the default cipher configuration uses weak temporary server 
keys (based on Diffie-Hellman key exchange protocol).

https://www.cloudera.com/documentation/enterprise/release-notes/topics/cdh_rn_os_ki.html#tls_weak_ciphers_rejected_by_oracle_linux_6



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

---------------------------------------------------------------------
To unsubscribe, e-mail: hdfs-dev-unsubscr...@hadoop.apache.org
For additional commands, e-mail: hdfs-dev-h...@hadoop.apache.org

Reply via email to