Skip to content

Keep static-RSA TLS suites enabled by default (eDirectory LDAPS) - #41

Merged
jcombs-pointblue merged 4 commits into
masterfrom
claude/legacy-tls
Oct 7, 2026
Merged

jcombs-pointblue merged 4 commits into
masterfrom
claude/legacy-tls

Conversation

@jcombs-pointblue

Copy link
Copy Markdown
Contributor

Jerry's bind to idm-ig4 failed with "simple bind failed" from a JDK that disables TLS_RSA_* (the web image's Temurin 21.0.12; JDK 24+ generally) while the same credentials bound from Azul 21.0.8. ig4's LDAPS offers only AES256-GCM-SHA384: ECDHE and TLS 1.3 handshakes are refused, so without static RSA there is nothing to agree on.

  • deploy/LegacyTls: removes TLS_RSA_* from jdk.tls.disabledAlgorithms once, before the TLS stack initialises — first thing in Cli.main, and before every Vault.connect. On by default, as Jerry decided ("we must accept older weaker ciphers by default"); opt out with -Didm.tls.legacy=false or IDM_TLS_LEGACY=false. Nothing else in the JDK's list changes.
  • doctor prints a tls: line saying whether the suites are kept.
  • Tests for the rule and the opt-out. The web server gets the same default in PointBlueTechnology/DirXMLDevWeb#62.

🤖 Generated with Claude Code

jcombs-pointblue and others added 4 commits October 7, 2026 17:04
…ners often offer nothing else

A bind to idm-ig4 failed with 'simple bind failed' on a JDK that disables TLS_RSA_* (Temurin
21.0.12, JDK 24+) while the same credentials bound on Azul 21.0.8. ig4 offers only
AES256-GCM-SHA384: no ECDHE, no TLS 1.3. LegacyTls.enable() runs first in Cli.main and before
every Vault connection; -Didm.tls.legacy=false / IDM_TLS_LEGACY=false opts out; doctor shows a
tls line.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…hout deploy

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jcombs-pointblue
jcombs-pointblue merged commit 14107d3 into master Oct 7, 2026
4 checks passed
@jcombs-pointblue

Copy link
Copy Markdown
Contributor Author

Merged into master locally with --no-ff and released as 0.14.0 (branch deleted, so GitHub shows this PR as closed).

@jcombs-pointblue
jcombs-pointblue deleted the claude/legacy-tls branch October 7, 2026 22:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant