First, I am already following the directions in this:
https://confluence.atlassian.com/kb/security-tools-report-the-default-ssl-ciphers-are-too-weak-755140945.html
We are seeing the following security issues:
arcfourarcfour128arcfour256
3des-cbcaes128-cbcaes192-cbcaes256-cbcblowfish-cbccast128-cbcrijndael-cbc@lysator.liu.se
hmac-md5hmac-md5-96hmac-sha1-96
It depends on what layer is providing your SSL.
If you are behind a proxy, consult the documentation on doing it for that proxy.
If you are just using the Tomcat that Confluence runs on, then the question becomes what are you doing differently to what the document has said you should do, and why?
It looks like you're new here. Sign in or register to get started.