-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Major
-
Affects Version/s: VOMS Clients v. 3.0.6, VOMS API Java v. 3.0.5
-
Component/s: api-java, clients-java
-
Security Level: Public (Visbile by non-authn users.)
-
None
SSLv3 is the protocol selected for legacy requests:
Normally this is not a problem, as TLS is selected for the HTTP request.
If the HTTP endpoint misbehaves (like it happens for the BNL and FNAL VOMS servers that likely have some configuration issues or use an old version
of the VOMS server where HTTP requests are not handled correctly), the fallback to the legacy protocol stops working on JREs that have SSLv3 disabled.