<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic alfresco CE 5.0.b - vti server jetty ( sharepoint) disable sslv3 in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-vti-server-jetty-sharepoint-disable-sslv3/m-p/280973#M234103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;hi ..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;env:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;os = centos 6.5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;alfresco = 5.0.b&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;vti server (jetty ) sharepoint = running in https port 7070&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;do any one know how to disable sslv3 (&amp;nbsp; POODLE SSLv3 Protocol CBC ciphers Information Disclosure Vulnerability ) on vti server ( jetty ). currently running on https .&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Vulnerability scanner detect as below , any solution to fix this . tq&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. POODLE SSLv3 Protocol CBC ciphers Information Disclosure Vulnerability&amp;nbsp; –&amp;gt; CVE: &amp;nbsp;&amp;nbsp;&amp;nbsp;CVE-2014-3566&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Missing Secure Attribute SSL Cookie Information Disclosure Vulnerability –&amp;gt; Workaround: Set the 'secure' attribute for any cookies that are sent over an SSL connection. how to set ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Check for SSL Weak Ciphers –&amp;gt; how to change to strong ssl ciphers&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Weak ciphers offered by this service:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; SSL3_RSA_RC4_128_MD5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; SSL3_RSA_RC4_128_SHA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; SSL3_ECDHE_RSA_WITH_RC4_128_SHA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; TLS1_RSA_RC4_128_MD5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; TLS1_RSA_RC4_128_SHA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; TLS1_ECDHE_RSA_WITH_RC4_128_SHA&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;4. Missing httpOnly Cookie Attribute –&amp;gt;solution, Set the 'httpOnly' attribute for any session cookies. how?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;hope some one able to help&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;tq ..&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Dec 2014 07:43:21 GMT</pubDate>
    <dc:creator>csyeow</dc:creator>
    <dc:date>2014-12-16T07:43:21Z</dc:date>
    <item>
      <title>alfresco CE 5.0.b - vti server jetty ( sharepoint) disable sslv3</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-vti-server-jetty-sharepoint-disable-sslv3/m-p/280973#M234103</link>
      <description>hi ..env&lt;IMG id="smileysurprised" class="emoticon emoticon-smileysurprised" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-surprised.png" alt="Smiley Surprised" title="Smiley Surprised" /&gt;s = centos 6.5alfresco = 5.0.bvti server (jetty ) sharepoint = running in https port 7070do any one know how to disable sslv3 (&amp;nbsp; POODLE SSLv3 Protocol CBC ciphers Information Disclosure Vulnerability ) on vti server ( jetty ). currently running on https .Vulnerability scanner detect as bel</description>
      <pubDate>Tue, 16 Dec 2014 07:43:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-vti-server-jetty-sharepoint-disable-sslv3/m-p/280973#M234103</guid>
      <dc:creator>csyeow</dc:creator>
      <dc:date>2014-12-16T07:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco CE 5.0.b - vti server jetty ( sharepoint) disable sslv3</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-vti-server-jetty-sharepoint-disable-sslv3/m-p/280974#M234104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;hi any one know how to add excludeCipherSuites &amp;amp; protocol–Default value is&amp;nbsp; "TLS" ( vti.server.xxx in alfresco-global.properties )&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i find the guide &lt;/SPAN&gt;&lt;A href="https://wiki.eclipse.org/Jetty/Howto/Configure_SSL" rel="nofollow noopener noreferrer"&gt;https://wiki.eclipse.org/Jetty/Howto/Configure_SSL&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;hope some one can help/ advise on this issue..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;tq&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Dec 2014 09:38:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-vti-server-jetty-sharepoint-disable-sslv3/m-p/280974#M234104</guid>
      <dc:creator>csyeow</dc:creator>
      <dc:date>2014-12-17T09:38:45Z</dc:date>
    </item>
  </channel>
</rss>

