Description
We should disable SSLv3 in KMS to protect against the POODLEbleed vulnerability.
See CVE-2014-3566
We have sslProtocol="TLS" set to only allow TLS in ssl-server.xml, but when I checked, I could still connect with SSLv3. There documentation is somewhat unclear in the tomcat configs between sslProtocol, sslProtocols, and sslEnabledProtocols and what each value they take does exactly. From what I can gather, sslProtocol="TLS" actually includes SSLv3 and the only way to fix this is to explicitly list which TLS versions we support.
Attachments
Attachments
Issue Links
- is related to
-
HDFS-7274 Disable SSLv3 in HttpFS
- Closed
- relates to
-
HADOOP-11218 Add TLSv1.1,TLSv1.2 to KMS, HttpFS, SSLFactory
- Resolved
-
HADOOP-11243 SSLFactory shouldn't allow SSLv3
- Closed