What are ciphers one should specify in Tomcat configuration, apart from
sslProtocols="TLSv1.2" sslEnabledProtocols="TLSv1.2" SSLEnabled="true"
The corresponding document has no recommendations for ciphers. Currently I see the latest Chrome reporting the below problem:
The connection to this site uses a strong protocol (TLS 1.2), a strong key exchange (ECDHE_RSA with P-256),
and an obsolete cipher (AES_128_CBC with HMAC-SHA1).
which means cipher list should be defined. Search over 'Net showed no definite up-to-date recommendations, all I have to do is to try list like
and experiment with adding/deleting ciphers, but if someone has better ideas, I would be glad to know.
The site is private and can't be checked directly (not allowed to do port forwarding to it); however, I tested A+ graded site and got the list of ciphers from the output.
Thanks, the answer is, as usually, obvious.
I attended Atlassian Summit 2019 and learned a lot from the presenters, attendees and knowledgeable Atlassian product managers. The presentations I attended focused on applying Agile, pla...
Connect with like-minded Atlassian users at free events near you!Find an event
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no Community Events near you at the moment.Host an event
You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events