[PROPOSAL] Change default SSLHostConfig.protocols

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

[PROPOSAL] Change default SSLHostConfig.protocols

Christopher Schultz-2
All,

For Tomcat 10 (only), I propose we change the default SSLHostConfig
protocols attribute from the current "SSLv2Hello, TLSv1, TLSv1.1,
TLSv1.2, TLSv1.3" to SSLv2Hello, TLSv1.2, TLSv1.3".

(That is, remove TLSv1 and TLSv1.1 from the default list.)

Any objections?

-chris

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: [PROPOSAL] Change default SSLHostConfig.protocols

markt
On 12/01/2021 19:31, Christopher Schultz wrote:
> All,
>
> For Tomcat 10 (only), I propose we change the default SSLHostConfig
> protocols attribute from the current "SSLv2Hello, TLSv1, TLSv1.1,
> TLSv1.2, TLSv1.3" to SSLv2Hello, TLSv1.2, TLSv1.3".
>
> (That is, remove TLSv1 and TLSv1.1 from the default list.)
>
> Any objections?

None here.

Mark

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]