浏览代码

HADOOP-11217. Disable SSLv3 in KMS. (Robert Kanter via kasha)

Karthik Kambatla 10 年之前
父节点
当前提交
1a78082338

+ 2 - 0
hadoop-common-project/hadoop-common/CHANGES.txt

@@ -1013,6 +1013,8 @@ Release 2.6.0 - UNRELEASED
     HADOOP-11170. ZKDelegationTokenSecretManager fails to renewToken created by 
     a peer. (Arun Suresh and Gregory Chanan via kasha)
 
+    HADOOP-11217. Disable SSLv3 in KMS. (Robert Kanter via kasha)
+
 Release 2.5.1 - 2014-09-05
 
   INCOMPATIBLE CHANGES

+ 1 - 1
hadoop-common-project/hadoop-kms/src/main/tomcat/ssl-server.xml

@@ -70,7 +70,7 @@
          described in the APR documentation -->
     <Connector port="${kms.http.port}" protocol="HTTP/1.1" SSLEnabled="true"
                maxThreads="${kms.max.threads}" scheme="https" secure="true"
-               clientAuth="false" sslProtocol="TLS"
+               clientAuth="false" sslEnabledProtocols="TLSv1"
                keystoreFile="${kms.ssl.keystore.file}"
                keystorePass="${kms.ssl.keystore.pass}"/>