Browse Source

HADOOP-11217. (Addendum to allow SSLv2Hello) Disable SSLv3 in KMS. (Robert Kanter via kasha)

Karthik Kambatla 10 năm trước cách đây
mục cha
commit
87818ef4e7

+ 1 - 1
hadoop-common-project/hadoop-kms/src/main/tomcat/ssl-server.xml

@@ -70,7 +70,7 @@
          described in the APR documentation -->
          described in the APR documentation -->
     <Connector port="${kms.http.port}" protocol="HTTP/1.1" SSLEnabled="true"
     <Connector port="${kms.http.port}" protocol="HTTP/1.1" SSLEnabled="true"
                maxThreads="${kms.max.threads}" scheme="https" secure="true"
                maxThreads="${kms.max.threads}" scheme="https" secure="true"
-               clientAuth="false" sslEnabledProtocols="TLSv1"
+               clientAuth="false" sslEnabledProtocols="TLSv1,SSLv2Hello"
                keystoreFile="${kms.ssl.keystore.file}"
                keystoreFile="${kms.ssl.keystore.file}"
                keystorePass="${kms.ssl.keystore.pass}"/>
                keystorePass="${kms.ssl.keystore.pass}"/>