Trying to make the SSLv3 and TLS protocols coexist

I have a customer who wants to remove their vulnerability to (among other things) POODLE by getting rid of SSLv3 for communicating with external vendors via their PI system, by restricting traffic to using the TLS protocol.
Unfortunately, not all their External Partners can meet this requirement, so temporarily, they want to have SSLv3 traffic (where still necessary) over one port and TLS traffic over another. The plan is that there will also be fire wall rules restricting the IP addresses of  "legacy partners" to the SSLv3 port. Following the instructions in 510007 - Setting up SSL on Application Server ABAP, they have installed SAPCRYPTOLIB version 5.5 and have set up the following configuration in DEFAULT.PFL:
* outgoing connections
ssl/ciphersuites = 135:HIGH
* incoming connections - TLS only protocol
icm/server_port_02 = PROT=HTTPS,PORT=443,SSLCONFIG=.........
icm/ssl_config_02 = CIPHERS=135:HIGH:MEDIUM:+e3DES
* incoming connections - SSL protocol
icm/server_port_01 = PROT=HTTPS,PORT=444,SSLCONFIG=.........
icm/ssl_config_01 = CIPHERS=196:HIGH:MEDIUM:+e3DES
So, what happens now is that f the External Partner attempts to initiate SSLv3 communications via port 443, then it fails. Yes, as currently setup, the External Partner can also initiate TLS communication over this port, but this is fine (for example, wireshark shows that the TLS protocol doesn't get downgraded to SSLv3).
The problem is that there is no way to control by port or customer whether outgoing connections are going to an SSLv3 or TLS only partner, so ssl/ciphersuites must allow for SSLv3 connections. This means that we can get a partner responding, over port 443, with the SSLv3 protocol without any error, thus allowing for an interception (ala POODLE).
Can we prevent SSLV3 traffic from succeeding over port 443, regardless of who initiates it ?

Hi,
I don't think that PI provides capabilities of setting allowed cipher suites per communication channel. Hence you can try to do this outside of SAP which brings additional complexity to your landscape. You could introduce a reverse proxy that would have hostnames like customer1.weakssl.local, customer2.weakssl.local for every customer that still needs SSLv3. This proxy would accept only TLS connection so you would be able to set ssl/client_ciphersuites to allow only strong suites. Your PI system would connect to partners with TLS or this reverse proxy only. The reverse proxy would drop TLS connection from PI and establish new connection SSLv3 between itself and customer. Hence PI would never use SSLv3 and the allowed SSLv3 outbound connections would be controlled by reverse proxy configuration.
PI ------------TLS----------------> Client that supports TLS
PI ------------TLS----->Reverse Proxy -----------SSLv3 ---------> Client that does not support TLS
Another disadvantage is that you will have to update PI config to connect via new reverse proxy instead of direct connection to customer's system.
Cheers

Similar Messages

  • HT1040 trying to make an ibook and have 800 photos, want format of 8 photos/page, but default is not that- "create" the initial book from iphoto "album" it loads less than 800 pics and then when i change layout i have blanks.

    trying to make an ibook and have 800 photos, want format of 8 photos/page, but default is not that- "create" the initial book from iphoto "album" it loads less than 800 pics and then when i change layout i have blanks.
    if i clear the book so that it is all blanks and then try to load in the pictures i have it loses the chronology of the pictures that i had established in the album.
    is there a way to import photos into an ibook template and keep the original order of the photos without having to do them one at a time?
    also, is there a way to insert a photo rather than just dragging it? i have tried the cut and paste funciton but it doesn't seem to work, the target site doesn't seem to register with iphoto.
    many thanks for your help.

    Photos are added to book in chronological order.  So if you want to add them to a book in the order you have placed them manually in an album do the following:
    1 - select all the photos in the album.
    2 - use the Photos ➙ Batch Change ➙ Date menu option as shown here. Select any date and add 1 minute between photos.
    3 - select just one photo from the album and create a book from it.
    4 - in the book click on the Options button ➙ Book Settings button and make sure the checkbox for Auto-layout pages is unchecked.
    5 - drag the album with your book photos onto the book icon and they will be imported into the Photos tray of the book in your pre-determined order but not into the pages themselves.
    OT

  • HT201412 I have to hit my home button a half dozen times to make it work.  I've tried to reset the phone and updated the software.  Is this a hardward problem?

    I have to hit my home button a half dozen times to make it work.  I've tried to reset the phone and update the sorfware.  Is this a hardware problem?  Where do I go to get it fixed?

    At Apple Store this is handled with Replacement iPhone exactly like yours. If there is AppleCare or Warranty it will be covered, otherwise there will be a charge of $150 - $199 depending on iPhone model. If iPhone 5 it will be covered. If you want to try Virtual Home Button. Settings App > General > Accessibility > Assistive Touch > ON > tap new white screen button > Home.

  • I'm trying to make a purchase and I get a message that the information does not match with the bank. What can I do?

    I'm trying to make a purchase and I get a message that the information does not match with the bank. What can I do?

    Go to the APP store or Itunes. On the bottom of the mainpage, tap your apple id, view account. Then you can edit the payment information. Or you can do it(if you encounter a problem there) on Itunes on computer. Just go to the store, select your name and edit information. Make sure everything matches...exp date, name as appears on card etc..

  • I am trying to make a purchase and want to use my Apple ID Balance and NOT charge the debit card under my account info.  How do I do this?

    I am trying to make a purchase and want to use my Apple ID Balance and NOT charge the debit card under my account info.  How do I do this?

    As far as I'm aware iTunes always charges the account balance first and when this expires charges any remaining amount to your credit/debit card. The one exception I am aware of (though there could be others) is that Apps purchased from the Canadian store must always be charged to a card rather than a gift card voucher balance due to local legislation.
    tt2

  • Tried to make a subnet and failed, now i can't re-connect to the internet

    i tried to extend the current network with my airport extreme, but the main router was not a mac product so it did not work. now i just want to re-connect with the main router so i can use the internet on my computer. the main network is still up and running for other people, i can access the network but am unable to use the internet.
    anyway to fix this? i already tried to restart the router, and the modem. unfortunately both attempts were unsuccessful.
    -thanks in advance

    Ok, you will not be able to extend the wireless range of the main router with your AEBS. What can be done is that you can connect the AEBS directly to this router using an Ethernet patch cable. If this is not the configuration that will work for you, then you will have to use a product that will perform this function from the same vendor as the main router.
    If your Mac is unable to get Internet access wirelessly from the main router then there may still be something amiss with the AirPort settings on your Mac. Like the Mac's built-in Ethernet, the built-in AirPort also must be configured as a DHCP client in order to "automatically" get the IP information from the main router.

  • Hi I am trying to change the margins and layout of an existing in design document, help!

    Hi I am trying to change the margins and layout of an existing in design document, help!

    This is an open forum, not Adobe support... you need Adobe support to help
    Adobe contact information - http://helpx.adobe.com/contact.html
    -Select your product and what you need help with
    -Click on the blue box "Still need help? Contact us"
    or
    Make sure that EVERY DETAIL is the same in every place you enter your information
    -right down to how you spell and punctuate the parts of your name and address
    Change/Verify Account https://forums.adobe.com/thread/1465499 may help
    -Credit card https://helpx.adobe.com/utilities/credit-card.html
    -email address https://forums.adobe.com/thread/1446019
    -http://helpx.adobe.com/x-productkb/global/didn-t-receive-expected-email.html

  • When I print a webpage from FF how can I make the text and images bigger?

    I am trying to print an eticket for a flight. The text on the schedule comes out too small and the UPC symbol's black lines look ganged together. I know I can view it zoomed up, but how do I make the text and images stay zoomed so they will print out that way?

    I upgraded but the problem remains. At least with Firefox I do have the option to print a selection even if it mangles the top and bottom lines. With Safari or Chrome I have no option to print a selection. At the moment the only way to get a complete copy of the selection is to copy to openoffice etc and print from there.

  • I am having trouble with my iPad, i can start it, but the iPad does not work. i tried to use the power and home button at the same time, the apple logo appears, but the iPad does not work. What am I suppose to do?

    I am having trouble with my iPad, i can start it, but the iPad does not work. i tried to use the power and home button at the same time, the apple logo appears, but the iPad does not work. What am I suppose to do?

    After the Apple logo appears, what happens then? Can you hear any sounds or if you tap on the screen, does it seem like apps can open or are you just seeing a black screen? You might have a hardware problem, but you can try restoring the software and see what happens.
    Read this in its entirety before you do anything. Make sure you read the sections at the end about using recovery mode.
    iTunes: Restoring iOS software - Support - Apple

  • Trying to make the jump from JPEG to RAW...

    Hi all, I'm trying to make the jump from JPEG to RAW, and am hoping you might be able to help with a few questions.
    When I open JPEGs in Lightroom's Develop module, the settings are mostly zero by default. But when I open RAW files, some of the settings seem to have non-zero default to values.
    Am I correct to think these settings are from metadata saved into the RAW file when I took the picture? eg, the camera saves the White Balance settings as metadata within the RAW file, even though the White Balance settings don't actually affect the image data itself. And so when I open that RAW file in Lightroom, it'll apply the White Balance as recorded within the file, making that a non-zero default.
    Is that about right?
    Does Lightroom similarly 'pre-set' other values when importing RAW files? (I ask because I seem to have non-zero settings for Blacks, Sharpening, as well as the Color slider under Noise Reduction.)
    Meaning: I'm not quite sure "how much work" Lightroom is doing by default when I import RAW files, and how much I need to do to at least reproduce what my camera would do in making a JPEG.
    For example, even though Color under Noise Reduction is given a value -- Luminance, also under under Noise Reduction, is left at zero. And the picture looks a bit grainy. Would my camera have processed some Luminance Noise Reduction? If so, is there a way to get Lightroom to help get that pre-set too?
    Basically, is there a rule of thumb for how a novice should import a RAW file and have it reasonably "at least as good" as what the JPEG would have been?
    Thanks very kindly, -Scott

    Given that the camera ships with so many special effect presets -- is there no built-in preset that could be named "Auto Camera" so to speak? Or might it be possible import such a preset that somebody else has made?
    Lightroom, nor any other third party raw processing program will not read the camera settings beyond simple stuff such as white balance. So you cannot do this. If you go raw, you really have to change your mindset and completely ignore the in-camera jpeg styles. Just set it to a neutral style and learn what the preview on the camera means for the actual raw data. You will find that this gives you orders of magnitude more creative freedom afterwards as you will not be stuck with a burned in interpretation.
    So (for me) even just making my own presets -- let alone making separate presets for every ISO -- all that seems a bit daunting.
    There really is no need to at all. I don't use presets for example. I think they are a waste of time as it is extremely rare that two images need exactly the same treatment. You really are just choosing a different starting point. I start all my raw at a relatively neutral setting (but using a camera profile generated from a colorchecker!) and blast through a shoot very quickly. You'll learn how to recognize what modifications to the Develop settings images need and just do it. Then typically I use auto-sync or manual sync to modify similar shots (say a series of head shots taken shortly after each other). I work differently as most of my photography is landscape, but a typical workflow for many photographers that do more people/style/event stuff is to import all the raw and start culling them with pick/reject flags and refine collection. You'll arrive at a subset that is worth looking  at more closely and to finetune their development. The conservative default rendering helps you here because you'll quickly see what images are simply badly exposed, not in correct focus, etc. and you can reject them.
    Think of your raw as the unprinted negative. It represents a nascent image. One that still has to form completely. A jpeg is like a polaroid. The image style is pretty much chosen for you by the film maker. There is very little you can do to it afterwards without it breaking down. Raw gives you much more freedom but it does come with a learning curve and it is more tasking for your equipment. Many people including many pros are simply not interested (or don't see the pay off) in this part of the creative photographic process and just shoot jpeg, which is a fine approach (just not mine). Lightroom can help you there too to quickly find the best images in a series, keyword, caption, and disseminate.

  • HT5824 Im trying to make the appointments on the calendar in my phone transfer to the icloud.if i reset my documents in icloud, can or will it delete data on my iphone?

    Im trying to make the appointments on the calendar in my phone transfer to the icloud calendar on my PC. If i reset my documents in icloud, can or will it delete data on my iphone?

    Hi jordanpaulbrown,
    I apologize, I'm a bit unclear on the exact configuration you are currently using/describing. If you are talking about My Photo Stream, you should be aware that it only stores stores photos for 30 days in order to allow for other device to connect and download the photos. If you would like to keep them long term off of your iPhone, you may want to set up your computer (Mac or Windows) to automatically download them. You may find the following article helpful:
    iCloud: My Photo Stream FAQ
    If you are running iOS 8 on your iPhone, you may also find the following article about changes to Photos useful:
    Get help finding your Photos in iOS 8
    Regards,
    - Brenden

  • HT3606 i keep trying to update the software and it gets stuck on configuration, so i can i sped up the process?

    i keep trying to update the software and it gets stuck on configuration, so i can i sped up the process?

    Some general advice on updating:
    It is worth noting that it is an extreme rarity for updates to cause upsets to your system, as they have all been extensively beta-tested, but they may well reveal pre-existing ones, particularly those of which you may have been unaware. If you are actually aware of any glitches, make sure they are fixed before proceeding further.
    So before you do anything else:
    If you can, make a full backup first to an external hard disk. Ideally you should always have a bootable clone of your system that enables you to revert to the previous pre-update state.
    Turn off sleep mode for both screen and hard disk.
    Disconnect all peripherals except your keyboard and mouse.
    1. Repair Permissions (in Disk Utility)
    2. Verify the state of your hard disk using Disk Utility. If any faults are reported, restart from your install disk (holding down the C key), go to Disk Utility, and repair your startup disk. Restart again to get back to your startup disk.
    At least you can now be reasonably certain that your system does not contain any obvious faults that might cause an update/upgrade to fail.
    3. Download the correct version of the COMBO update from the Apple download site.
    The Combo updater of Leopard 10.5.8 can be found here:
    http://support.apple.com/downloads/Mac_OS_X_10_5_8_Combo_Update
    If you prefer to download updates via Software Update in the Apple menu (which would ensure that the correct version for your Mac was being downloaded), it is not recommended to allow SU to install major (or even minor) updates automatically. Set Software Update to just download the updater without immediately installing it. There is always the possibility that the combined download and install (which can be a lengthy process) might be interrupted by a power outage or your cat walking across the keyboard, and an interrupted install will almost certainly cause havoc. Once it is downloaded, you can install at a time that suits you. You should make a backup copy of the updater on a CD in case you ever need a reinstall.
    Full details about the 10.5.8 update here: http://support.apple.com/kb/HT3606
    More information on using Software Updater here:
    http://support.apple.com/kb/TA24901?viewlocale=en_US
    Using the Combo updater ensures that all system files changed since the original 10.5.0 are included, and any that may have been missed out or subsequently damaged will be repaired. The Delta updater, although a temptingly smaller download, only takes you from the previous version to the new one, i.e. for example from 10.5.7 to 10.5.8. Software Update will generally download the Delta updater only. The preferable Combo updater needs to be downloaded from Apple's download site.
    Now proceed as follows:
    4. Close all applications and turn off energy saving and screensaver.
    5. Unplug all peripherals except your keyboard and mouse.
    6. Install the update/upgrade. Do not under any circumstances interrupt this procedure. Do not do anything else on your computer while it is installing. Be patient.
    7. When it ask for a restart to complete the installation, click restart. This can take longer than normal, there are probably thousands of files to overwrite and place in the correct location. Do nothing while this is going on.
    8. Once your Mac is awake, repair permissions again, and you should be good to go!
    If your Mac seems slightly sluggish or ‘different’, perform a second restart. It can’t hurt and is sometimes efficacious! In fact a second restart can be recommended.
    9. Open a few of your most used applications and check that all is OK. In this connection please remember that not all manufacturers of third party applications and plug-ins, add-ons, haxies etc, will have had time to do any necessary rewrites to their software to make them compliant with the latest version of your operating system. Give them a week or two while you regularly check their websites for updates.
    N.B. Do not attempt to install two different updates at the same time as each may have different routines and requirements. Follow the above recommendations for each update in turn.
    Lastly, Apple's own article on the subject of Software Update may also be useful reading:
    http://docs.info.apple.com/article.html?artnum=106695
    [b]If you are updating Safari (or just have):[/b]
    Input Managers from third parties can do as much harm as good. They use a security loophole to reach right into your applications' code and change that code as the application starts up.  If you have installed an OS update and Safari is crashing, the very [i]first[/i] thing to do is clear out your InputManagers folders (both in your own Library and in the top-level /Library), log out and log back in, and try again.
    So, disable all third party add-ons before updating Safari, as they may not have been updated yet for the new version. Add them back one by one. If something goes awry, remove it again and check on the software manufacturer's website for news of an update to match your version of Safari.
    Most errors reported here after an update are due to an unrepaired or undetected inherent fault in the system, and/or a third party add-on.
    Additional tips on software installation here:
    http://docs.info.apple.com/article.html?artnum=106692
    To reiterate, Input Managers reach right into an application and alter its code. This puts the behavior of the affected application outside the control and responsibility of its developers: a recipe for  problems. That's not to say that issues absolutely will ensue as a result of Input Managers, but you, as a user, must decide. If the functionality of a specific Input Manager or set thereof is really important to you, you may well choose to assume the associated risk.
    Again, the advice is to remove all Input Managers from the following directories:
    /Library/InputManagers
    ~/Library/InputManagers
    especially prior to system updates (they can always be added back one-by-one later).
    Solutions for troubleshooting installation, startup, and login issues in Mac OS X v10.5
    http://support.apple.com/kb/TS1541?viewlocale=en_US

  • Since Upgrading to Ios5 i cannot open my contacts! i have tried to disable the Icloud and still they do not open! anyone have any further ideas for me to try?

    Since i updated my Iphone 4S to IoS5 i cannot open my contacts! i have tried to disable the Icloud and still they do not open! anyone have any further ideas for me to try?

    Check the age of the files you wish to open.
    Keynote 6 (the latest you downloaded) will opne Keynote 5 (KN09) files but nothing earlier. For that KN5 will act as an intermediate format (you save KN4 and earlier as KN5), then KN6 can open the resultanr files.
    Make sure you have a backup of your original files, in case KN6 cannot replicate some of your earlier builds and transitions.
    Les

  • HT1750 I tried to change the memory and now my Imac will not power on. and there are no beeps. what did I do wrong?

    I tried to change the memory and now my Imac will not power on. and there are no beeps. what did I do wrong?

    Don't know.  Could be any number of reasons.  Re-read the how to install RAM manual again for your model iMac.  Double & triple check to make sure you purchased the right RAM chips.   Make sure they are seated properly.  If you didn't hear a snap when seated, the RAM is not properly seated. 

  • What do I need to do to my CSS to make the Georgia and Verdana fonts on my website show correctly in Firefox?

    Why does my website's css font styling not look right in Firefox but looks right in Explorer? What do I need to do to my CSS to make the Georgia and Verdana fonts show? Right now they show as Times Roman in Firefox. I tried using all the font attributes combined in a single font property and then I separated out the font-family, font-size, etc. and neither way made them look right in Firefox.

    A good place to ask questions and advice about web development is at the MozillaZine Web Development/Standards Evangelism forum.
    The helpers at that forum are more knowledgeable about web development issues.
    You need to register at the MozillaZine forum site in order to post at that forum.
    See http://forums.mozillazine.org/viewforum.php?f=25

Maybe you are looking for

  • One item used for insert and update

    I'm still trying to learn APEX and need to understand how to use an item for both update and insert. Is the LOV part used for the insert and the SOURCE for the update? I have a WHERE clause I need to use for the insert but not the update. I have to d

  • Keep getting hardisk crash messages at startup

    keep getting hardisk crash messages when i startup. have run software programs which do not seem to indicate problems once I have logged in

  • MacBook Pro Not turning on, loud fan

    My friends 13in MacBook Pro won't turn on. The light on the bottom near the remote reciever is on and there is a very loud fan noise.

  • Changing readonly property

    Hi, To keep a field readonly when it has some value, I created a boolean value attribute in context, and assigned to the input field. I am setting boolean attribute to true if string ! = null. But I am not achieving this. I am getting either readonly

  • WD 2 TB External Drive

    I cannot get this thing to mount when I plug it in.... Is there a way to force this to mount? I can see it in drive manager. Please help.