It's not a secret anymore!*
The moose likes Other Java Products and Servers and the fly likes Sesion renegotiation and JDK 1.6 20 with Pramati 5.0 SP3 Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login


Win a copy of Android Security Essentials Live Lessons this week in the Android forum!
JavaRanch » Java Forums » Products » Other Java Products and Servers
Bookmark "Sesion renegotiation and JDK 1.6 20 with Pramati 5.0 SP3" Watch "Sesion renegotiation and JDK 1.6 20 with Pramati 5.0 SP3" New topic
Author

Sesion renegotiation and JDK 1.6 20 with Pramati 5.0 SP3

Ajit Kanada
Ranch Hand

Joined: Jan 23, 2001
Posts: 95
Hi,

We have added Dsun.security.ssl.allowUnsafeRenegotiation=false in our Pramati Server startup script and its using
JDK 1.6_20.

With JDK 1.6_20 Session renegotiation is disabled by default.But in a security audit our server was found vulnerable to "Sesion renegotiation attack".

Any clues if this is a problem with the fix which is present in JDK 1.6_20 ?

Ajit


Thankx
Ajit
 
I agree. Here's the link: http://aspose.com/file-tools
 
subject: Sesion renegotiation and JDK 1.6 20 with Pramati 5.0 SP3
 
Similar Threads
java.rmi.ConnectException: Connection refused to host
java.rmi.ConnectException
anyone knows Pramati Application server ?
JBOSS
Contract Renegotiation