Repository navigation
Keep static-RSA TLS suites enabled by default (eDirectory LDAPS) - #41
Merged
Merged
Conversation
…ners often offer nothing else A bind to idm-ig4 failed with 'simple bind failed' on a JDK that disables TLS_RSA_* (Temurin 21.0.12, JDK 24+) while the same credentials bound on Azul 21.0.8. ig4 offers only AES256-GCM-SHA384: no ECDHE, no TLS 1.3. LegacyTls.enable() runs first in Cli.main and before every Vault connection; -Didm.tls.legacy=false / IDM_TLS_LEGACY=false opts out; doctor shows a tls line. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…hout deploy Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Contributor
Author
|
Merged into master locally with |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Jerry's bind to idm-ig4 failed with "simple bind failed" from a JDK that disables
TLS_RSA_*(the web image's Temurin 21.0.12; JDK 24+ generally) while the same credentials bound from Azul 21.0.8. ig4's LDAPS offers onlyAES256-GCM-SHA384: ECDHE and TLS 1.3 handshakes are refused, so without static RSA there is nothing to agree on.deploy/LegacyTls: removesTLS_RSA_*fromjdk.tls.disabledAlgorithmsonce, before the TLS stack initialises — first thing inCli.main, and before everyVault.connect. On by default, as Jerry decided ("we must accept older weaker ciphers by default"); opt out with-Didm.tls.legacy=falseorIDM_TLS_LEGACY=false. Nothing else in the JDK's list changes.doctorprints atls:line saying whether the suites are kept.🤖 Generated with Claude Code