Details
Description
At the moment TSSLSocket.cpp hard-codes the SSL/TLS protocol to TLSv1.0, which does not allow any other protocols to be used instead (SSL v3, TLS v1.0, v1.1, v1.2, ignores SSLv2 as horribly insecure).
Could a method be provided on the TSSLSocketFactory to set the required protocol (like how there is already a cipher() function available), so that when SSL_CTX_new, it is called with the specified SSL/TLS protocol.
Sorry to label this as a bug, but being unable to select the highest availabe security protocol for communication is a bug in my eyes.
Attachments
Attachments
Issue Links
- is related to
-
THRIFT-2325 SSL test certificates
- Closed