Forum Discussion
tdsacilowski_17
Nimbostratus
Dec 10, 2014HTTPS Monitor fails after disabling SSLv3 on Tomcat 7 (APR connector)
I'm currently in the process of upgrading my Tomcat servers to Tomcat 7 using the APR connector with SSLv3 disabled. Here is my connector:
Everything seems to be working properly... e.g. going to ...
tdsacilowski_17
Nimbostratus
Dec 11, 2014Seems to be an issue with the Tomcat APR connector. I switched to NIO and added the following in my connector config:
sslProtocol="TLS" sslEnabledProtocols="TLSv1.2,TLSv1.1,TLSv1,SSLv2Hello"
Once I made this change the monitor kicked in immediately. Specifically, it seems that the issue is with the SSLv2Hello handshake. When I removed it from my config the monitor stopped working. This tells me the monitor is relying on the SSLvHello handshake. Is there any way to force the monitor to use TLSv1 instead? I tried specifying that in the cipher list but it didn't seem to help.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects