Geek Boy's blog
Thursday, October 23, 2008
  Fun with IE6, SSLv2 and TLSv1
Internet Explorer pain

A consulting client of mine has a website with some security requirements that mandate the use of encrypted communications. The site had been running on Tomcat 4 on a Win2K server machine, with no particular tuning of how tomcat dealt with crypto. We kinda just dropped in the server-side cert and ran with it, back in 2003 or so.

We recently ran a nessus scan on the machine, which suggested that allowing SSL2 and weak ciphers was perhaps a bad idea. We were intending to retire the Win2K machine anyway and do some other software updates, so we decided to deal with this too. The new machine is a Win2003 R2 server running inside of VMWare, with Tomcat 6 running in a Java 6 JVM, and using the APR connecter rather than the tomcat standard connector.

We initially deployed with the following configuration:


<Connector port="443" protocol="org.apache.coyote.http11.Http11AprProtocol"
SSLEnabled="true" compression="on"
maxThreads="150" scheme="https" secure="true"
SSLProtocol="TLSv1"
SSLCipherSuite="HIGH:!SSLv2:!ADH:!aNULL:!eNULL:!NULL"
SSLCertificateKeyFile="conf/privatekey.key"
SSLCertificateFile="conf/site.crt"
SSLPassword="i_can_haz_crypto_k_thx_bye" />



this worked great with IE7, Firefox 2+, and Safari, but IE6 acted as if it couldn't find the site at all - as if it failed DNS resolution! We had some difficulty figuring out what was going on, but we ended up turning on SSLv3 as well as just TLSv1 in the SSLProtocol setting, like so:


<Connector port="443" protocol="org.apache.coyote.http11.Http11AprProtocol"
SSLEnabled="true" compression="on"
maxThreads="150" scheme="https" secure="true"
SSLProtocol="ALL -SSLv2"
SSLCipherSuite="HIGH:!SSLv2:!ADH:!aNULL:!eNULL:!NULL"
SSLCertificateKeyFile="conf/privatekey.key"
SSLCertificateFile="conf/site.crt"
SSLPassword="i_can_haz_crypto_k_thx_bye" />



and then things seemed much happier. This was particularly confusing, as our IE6 machine had "Support TLS" checked in the Tools->Internet Options->Advanced settings pane. Still not entirely sure what's going on, but turning on SSLv3 and leaving SSLv2 off appears to work.

Time to upgrade the world to Firefox.

Labels:

 
Various ramblings from Peter Clark about life, coding, parenthood, Java, grad school, and enjoying my mac book air

Name: Peter Clark

Terror Alert Level

Thao and the Get Down Stay Down -- When We Swam

Archives
09/01/2003 - 10/01/2003 / 10/01/2003 - 11/01/2003 / 11/01/2003 - 12/01/2003 / 12/01/2003 - 01/01/2004 / 01/01/2004 - 02/01/2004 / 02/01/2004 - 03/01/2004 / 03/01/2004 - 04/01/2004 / 04/01/2004 - 05/01/2004 / 05/01/2004 - 06/01/2004 / 06/01/2004 - 07/01/2004 / 07/01/2004 - 08/01/2004 / 08/01/2004 - 09/01/2004 / 09/01/2004 - 10/01/2004 / 10/01/2004 - 11/01/2004 / 11/01/2004 - 12/01/2004 / 12/01/2004 - 01/01/2005 / 01/01/2005 - 02/01/2005 / 02/01/2005 - 03/01/2005 / 03/01/2005 - 04/01/2005 / 04/01/2005 - 05/01/2005 / 05/01/2005 - 06/01/2005 / 06/01/2005 - 07/01/2005 / 07/01/2005 - 08/01/2005 / 08/01/2005 - 09/01/2005 / 09/01/2005 - 10/01/2005 / 10/01/2005 - 11/01/2005 / 11/01/2005 - 12/01/2005 / 12/01/2005 - 01/01/2006 / 01/01/2006 - 02/01/2006 / 02/01/2006 - 03/01/2006 / 03/01/2006 - 04/01/2006 / 04/01/2006 - 05/01/2006 / 05/01/2006 - 06/01/2006 / 06/01/2006 - 07/01/2006 / 09/01/2006 - 10/01/2006 / 10/01/2006 - 11/01/2006 / 11/01/2006 - 12/01/2006 / 12/01/2006 - 01/01/2007 / 01/01/2007 - 02/01/2007 / 02/01/2007 - 03/01/2007 / 03/01/2007 - 04/01/2007 / 04/01/2007 - 05/01/2007 / 05/01/2007 - 06/01/2007 / 06/01/2007 - 07/01/2007 / 07/01/2007 - 08/01/2007 / 08/01/2007 - 09/01/2007 / 10/01/2007 - 11/01/2007 / 11/01/2007 - 12/01/2007 / 12/01/2007 - 01/01/2008 / 02/01/2008 - 03/01/2008 / 03/01/2008 - 04/01/2008 / 04/01/2008 - 05/01/2008 / 05/01/2008 - 06/01/2008 / 06/01/2008 - 07/01/2008 / 07/01/2008 - 08/01/2008 / 09/01/2008 - 10/01/2008 / 10/01/2008 - 11/01/2008 / 11/01/2008 - 12/01/2008 / 12/01/2008 - 01/01/2009 / 01/01/2009 - 02/01/2009 / 02/01/2009 - 03/01/2009 / 03/01/2009 - 04/01/2009 / 04/01/2009 - 05/01/2009 / 05/01/2009 - 06/01/2009 / 06/01/2009 - 07/01/2009 / 07/01/2009 - 08/01/2009 / 08/01/2009 - 09/01/2009 / 10/01/2009 - 11/01/2009 / 11/01/2009 - 12/01/2009 / 12/01/2009 - 01/01/2010 / 03/01/2010 - 04/01/2010 /


Powered by Blogger

Subscribe to
Posts [Atom]