RE: SSLv3/TLS man-in-middle vulnerability

2010-01-19 Thread Steve G. Johnson
List" Caterpillar: Confidential Green Retain Until: 02/18/2010 > From: Steve G. Johnso

Re: SSLv3/TLS man-in-middle vulnerability

2010-01-19 Thread Steve G. Johnson
01/2010 02:31, Steve G. Johnson wrote: > Mark, > Since we do not know how to "switch connectors", or install OpenSSL, and do > not have JDK on the server (only JRE 1.6.0_17), then I suppose the best bet > is to wait until Tomcat is fixed ("coming soon"). You can

Re: SSLv3/TLS man-in-middle vulnerability

2010-01-18 Thread Steve G. Johnson
Until: 02/17/2010 On 18/01/2010 11:03, Steve G. Johnson wrote: > > We recently installed Tomcat 5.5.23 in Windows server to support the Infor > WebUI (webtop) application. > We installed a cerificate and are using SSl on port 8443. This all works > fine. > > The local IT Se

SSLv3/TLS man-in-middle vulnerability

2010-01-18 Thread Steve G. Johnson
We recently installed Tomcat 5.5.23 in Windows server to support the Infor WebUI (webtop) application. We installed a cerificate and are using SSl on port 8443. This all works fine. The local IT Security team ran an HP "Web Inspect" and it showed a High vulnerability for SSLv3/TLS known as CVE-20