Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1218348

Summary: Backport "TLSv1.1" and "TLSv1.2" support to EWS 2.0.1
Product: [JBoss] JBoss Enterprise Web Server 2 Reporter: Phil Festoso <philfest>
Component: httpdAssignee: Weinan Li <weli>
Status: CLOSED CURRENTRELEASE QA Contact: Michal Karm Babacek <mbabacek>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 2.0.1CC: bbaranow, csutherl, erich, fgoldefu, jawilson, jclere, jdoyle, lcosti, lfuka, myarboro, pslavice, rmarwaha, rsvoboda, weli
Target Milestone: ---   
Target Release: 3.0.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1038651 Environment:
Last Closed: 2017-08-08 20:01:40 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1218346    
Bug Blocks:    

Description Phil Festoso 2015-05-04 16:46:57 UTC
+++ This bug was initially created as a clone of Bug #1038651 +++

+++ This bug was initially created as a clone of Bug #1038648 +++

Description of problem:

Customer was recently asked by their security team to update their EAP-Apache environments using SSL to use TLSv1.1/1.2. While updating APAWS6.2- environments, customer discovered that apache 2.2.22 does not support TLSv1.1/1.2. Customer opened a support case #01436249 and the recommendation was to upgrade apache to 2.2.26 (EAPWS6.3/EWS2.1.0). 

Customer currently do not support apache 2.2.26 as a solution and the task of manually updating webserver version is not an option for them due to the magnitude of effort involved.  Customer needs Redhat to provide us a patch backporting the fix for support of TLSv1.1/1.2 to apache 2.2.22/2.2.17 (APAWS6.2-/EWS2.0.1/EWS1.0.2). In the absence of this, our JBoss environments will be in non-compliance with our security team.

Customer has ELS entitlements for EWS. They use they zip distributions of the product and they run on RHEL.

Separate RFEs will be filed for both 1.0.2 and 2.1.0. This RFE covers the request for 2.0.1. Please see BZ 1218346 for the request for the 1.0.2 backport.