Re: Client-cert, ciphers, and proxies

2014-04-28 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Gary, On 4/27/14, 11:05 PM, Gary Briggs wrote: > In short: What's the best way to configure ciphers, matching in > tomcat and openssl, to get widest browser compatability without > sacrificing security? > > In long: I'm running tomcat with client-c

Re: Client-cert, ciphers, and proxies

2014-04-27 Thread Mark Thomas
On 28 April 2014 04:05:35 GMT+01:00, Gary Briggs wrote: >In short: What's the best way to configure ciphers, matching in tomcat >and openssl, to get widest browser compatability without sacrificing >security? Check configuration with https://www.ssllabs.com/ssltest/ Mark --

Client-cert, ciphers, and proxies

2014-04-27 Thread Gary Briggs
In short: What's the best way to configure ciphers, matching in tomcat and openssl, to get widest browser compatability without sacrificing security? In long: I'm running tomcat with client-certificate authentication behind a proxy made by F5 [LTM, "Local Traffic Manager", is the specific product]