'tomcatjss' is currently utilized by 'pki-ca', 'pki-kra', 'pki-ocsp', and 'pki-tks'. Examination of the code revealed that DES ciphers populated to 'server.xml' for 'pki-ca', 'pki-kra', 'pki-ocsp', and 'pki-tks' per 'pkiparser.py'/'pkicreate' include:


    NOTE: '-' in front of cipher means explicitly disabled,
          '+' in front of cipher means explicitly enabled

Consider disabling '+SSL3_RSA_WITH_DES_CBC_SHA' as '-SSL3_RSA_WITH_DES_CBC_SHA' in 'pkiparser.py' and 'pkicreate'.

This ticket was extracted from https://fedorahosted.org/pki/ticket/700 - TRAC Ticket #700 - Disable all DES-based ciphers.

checked into master:

  • 443bffbe31971a66ce7b83c3f447057957b121cb

Metadata Update from @mharmsen:
- Issue assigned to mharmsen
- Issue set to the milestone: 10.1 - 08/13 (August)

