Uploaded image for project: 'AMQ Interconnect'
  1. AMQ Interconnect
  2. ENTMQIC-1990

Allow restriction of TLS and SSL protocol versions to be used in connections

    XMLWordPrintable

Details

    • ToDo fill in Epic name
    • Documentation (Ref Guide, User Guide, etc.), Release Notes
    • Done
    • 0
    • 0% 0%
    • In this version of AMQ Interconnect, you can now specify the SSL/TLS protocol version to be used in connections. You can use this capability to block versions of the protocol that have been shown to have security vulnerabilities.
    • Documented as Feature Request

    Description

      User Story:
      As a deployer, my company has a security policy that requires a particular version of TLS to be used in network security. I need to configure my routers to use only that TLS version. If there is no available subset between client and server, I expect a clear audit log entry to tell me that a connection failed. I expect the default value to be reasonably secure.

      Reference:
      https://issues.apache.org/jira/browse/DISPATCH-884

      Allow the deployer to configure the set of permitted TLS/SSL protocol versions that may be used in connections to the router.

      Attachments

        Issue Links

          Activity

            People

              gmurthy@redhat.com Ganesh Murthy
              tross1@redhat.com Ted Ross
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: