Allow configuring excluded ciphers and SSL protocols#66
Allow configuring excluded ciphers and SSL protocols#66Grigoriy Roghkov (groghkov) wants to merge 1 commit intoconfluentinc:masterfrom
Conversation
|
It looks like Grigoriy Roghkov (@groghkov) hasn't signed our Contributor License Agreement, yet.
You can read and sign our full Contributor License Agreement here. Once you've signed reply with Appreciation of efforts, clabot |
|
Can one of the admins verify this patch? |
|
ok to test |
|
Can one of the admins verify this patch? |
|
Test FAILed. |
Ewen Cheslack-Postava (ewencp)
left a comment
There was a problem hiding this comment.
LGTM, but there's a trivial checkstyle issue. Grigoriy Roghkov (@groghkov) do you also want to retarget to 3.4.x branch, which will get this in a release sooner?
Protocol and ciphers come from JDK. JDK can add new protocols/ciphers at any time.
If we use only inclusion lists we block support of new protocols/ciphers because they will not be in inclusion list and application will ignore theirs.
We need to use exclusion lists so that we don’t block out future support.