Bug 907532 - Add support for SSLv3 when Apache is not used as proxy
Add support for SSLv3 when Apache is not used as proxy
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: ovirt-engine-setup (Show other bugs)
Unspecified Unspecified
high Severity unspecified
: ---
: 3.1.3
Assigned To: Juan Hernández
Pavel Stehlik
: ZStream
Depends On: 893979
  Show dependency treegraph
Reported: 2013-02-04 11:13 EST by Idith Tal-Kohen
Modified: 2013-11-27 18:59 EST (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Previously, if Apache was not used as the proxy for the application server, the HTTPS connector would only configure TLSv1 protocol. Connections to the application server using SSLv3 protocol would fail. Now, SSLv3 is supported and can be used to connect to the application server.
Story Points: ---
Clone Of: 893979
Last Closed: 2013-03-12 10:29:15 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
oVirt gerrit 10858 None None None Never

  None (edit)
Comment 2 Juan Hernández 2013-02-11 11:26:36 EST
Note that the option to disable TLSv1 isn't -no_tlsv1 but -no_tls1 (without the v). Check the s_client manual page for details. So the complete command to do the test should be like this:

  openssl s_client -connect f17.example.com:8701 -no_tls1
Comment 5 errata-xmlrpc 2013-03-12 10:29:15 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.