Identity Management (MOSC)

MOSC Banner

Does OUD care about TLS cipher ordering?

edited Mar 11, 2019 4:41PM in Identity Management (MOSC) 8 commentsAnswered

Hi,

an auditor is asking me whether it's able to force an order of cipher preference server-side in OUD.

The intention is obviously to force the selection of strong ciphers even where clients are misconfigured.

So, I'm looking at the OUD configuration, but where tools.properties has a concatenated string of ciphers (in a certain order) connection handlers in cn=config have a multivalued attribute on the server side (which doesn't have any internal order.) So, that kinda seems to suggest we have the old model here, where the order of preference is determined by the client.

Java itself can make the server chose by its own preference.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center