Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
3.6.0, 3.5.5
-
None
Description
Client-initiated TLS renegotiation is not secure and exposes the connection to MITM attacks. Unfortunately, Java's TLS implementation allows it by default. Thankfully, it is easy to disable.