LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-19-2015, 02:27 AM   #1
Iyyappan
Member
 
Registered: Dec 2008
Location: Chennai, India
Distribution: CentOS 5, SLES 11
Posts: 245

Rep: Reputation: 4
Disabling SSLv3 in Java


We are using apache2 with reverse proxy as front end and tomcat 6 as backend. Java used is jdk1.6.0_38. SSL is used only in webserver and there is no SSL in tomcat

Post disabling SSLv3 in http server, poodle issue got fixed.


We have two environments TEST1 and TEST2. In Test 1 and Test 2 SSLv3 is disabled. From TEST 2 tomcat a request is being sent to TEST 1 via https://TEST1/something.

When this happens, I get below errors in tomcat logs

2015-02-19 02:29:00|ERROR|c.m.e.b.a.LoadTasklet|loadAssociatesSchedulerFactory_Worker-1|Exception :::
com.sun.jersey.api.client.ClientHandlerException: javax.net.ssl.SSLHandshakeException: Remote host closed connection during handshake
at com.sun.jersey.client.urlconnection.URLConnectionClientHandler.handle(URLConnectionClientHandler.jav a:151) ~[jersey-client-1.17.1.jar:1.17.1]
at com.sun.jersey.api.client.Client.handle(Client.java:648) ~[jersey-client-1.17.1.jar:1.17.1]
at com.sun.jersey.api.client.WebResource.handle(WebResource.java:680) ~[jersey-client-1.17.1.jar:1.17.1]
at com.sun.jersey.api.client.WebResource.access$200(WebResource.java:74) ~[jersey-client-1.17.1.jar:1.17.1]


Caused by: javax.net.ssl.SSLHandshakeException: Remote host closed connection during handshake
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:882) ~[na:1.6]
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1203) ~[na:1.6]
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1230) ~[na:1.6]
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1214) ~[na:1.6]


There is no SSL configurations anywhere in web server/tomcat (confirmed by my application team), but I am seeing SSL errors in logs, I am not sure from where its getting logged. I suspect its coming from jdk-1.6


If I enabled SSLv3 in both TEST1 and TEST2, application starts to work fine.
 
Old 03-03-2015, 05:38 PM   #2
linuxtech99
Member
 
Registered: Jan 2015
Posts: 35

Rep: Reputation: 4
Your issue might be related to http://stackoverflow.com/questions/2...-during-handsh. Let me know this solution fixes your issue.
 
Old 03-06-2015, 04:31 AM   #3
Iyyappan
Member
 
Registered: Dec 2008
Location: Chennai, India
Distribution: CentOS 5, SLES 11
Posts: 245

Original Poster
Rep: Reputation: 4
All certificates are available. Issue is cropping only when SSLv3 is disabled
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
After disabling SSLv3 Apache Jmeter not able to connect to Apache httpd Iyyappan Linux - Server 3 01-19-2015 09:30 AM
SSLv3 Vulnerability (CVE-2014-3566, POODLE) Linux_Kidd Linux - News 5 12-10-2014 12:54 PM
Cannot open .jnlp OR Disabling Java as it is too old and likely to be out of date. czezz Linux - Desktop 0 12-10-2014 12:44 PM
webservers SSLv3 disabled but under reverse proxy depam Linux - Security 2 10-19-2014 05:11 AM
Courier-imaps using TLS or SSLv3 ? scoop_yo Linux - Security 1 01-29-2009 02:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration