ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » News/Updates » SSL / TLS vulnerability du jour

Post new topic  Reply to topic
 SSL / TLS vulnerability du jour « View previous topic :: View next topic » 
Author Message
PeterPotkay
PostPosted: Tue Nov 04, 2014 7:40 am    Post subject: SSL / TLS vulnerability du jour Reply with quote

Poobah

Joined: 15 May 2001
Posts: 7722

http://www-01.ibm.com/support/docview.wss?uid=swg21688949&myns=swgws&mynp=OCSSFKSJ&mync=E


Here is the list of available CipherSpecs for MQ 7.5
http://www-01.ibm.com/support/knowledgecenter/SSFKSJ_7.5.0/com.ibm.mq.sec.doc/q014260_.htm

Now cross off MD5, SSL v3, ones that start with 'EC', look at SHA-1 only if you plan to retire them in a couple of years.....like half the CipsherSpecs are no good!
_________________
Peter Potkay
Keep Calm and MQ On
Back to top
View user's profile Send private message
tczielke
PostPosted: Tue Nov 04, 2014 8:09 am    Post subject: Reply with quote

Guardian

Joined: 08 Jul 2010
Posts: 941
Location: Illinois, USA

I think the security community (or some in the security community) frown on TLS 1.0, too. I agree, there are hardly any left. I guess at some point you have to pick one and just use it.
Back to top
View user's profile Send private message
mqjeff
PostPosted: Tue Nov 04, 2014 8:30 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

Security is about risk management.

You simply can't protect against zero-day exploits.

So you make the best efforts you can, and reevaluate frequently.
Back to top
View user's profile Send private message
tczielke
PostPosted: Tue Nov 04, 2014 8:37 am    Post subject: Reply with quote

Guardian

Joined: 08 Jul 2010
Posts: 941
Location: Illinois, USA

The way that MQ locks you into specifying just one cipher that has to match on both the sender and receiver channel end, does make it difficult to be constantly changing that cipher spec, especially when you start to bring in third parties and client applications into the mix.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » News/Updates » SSL / TLS vulnerability du jour
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.