Fuse 6 is no longer supported
As of February 2025, Red Hat Fuse 6 is no longer supported. If you are using Fuse 6, please upgrade to Red Hat build of Apache Camel.このコンテンツは選択した言語では利用できません。
4.3. SSL/TLS Protocol Version
Overview
リンクのコピーリンクがクリップボードにコピーされました!
				The versions of the SSL/TLS protocol that are supported by Apache CXF depend on the particular JSSE provider configured. By default, the JSSE provider is configured to be SUN’s JSSE provider implementation.
			
SSL/TLS protocol versions supported by SunJSSE
リンクのコピーリンクがクリップボードにコピーされました!
				Table 4.2, “SSL/TLS Protocols Supported by SUN’s JSSE Provider” shows the SSL/TLS protocol versions supported by SUN’s JSSE provider.
			
| Protocol | Description | 
|---|---|
| SSLv2Hello | 
								Do not use! (POODLE security vulnerability)
							 | 
| SSLv3 | 
								Do not use! (POODLE security vulnerability)
							 | 
| TLSv1 | 
								Supports TLS version 1
							 | 
| TLSv1.1 | Supports TLS version 1.1 (JDK 7 or later) | 
| TLSv1.2 | Supports TLS version 1.2 (JDK 7 or later) | 
Excluding specific SSL/TLS protocol versions
リンクのコピーリンクがクリップボードにコピーされました!
				Because of the Poodle vulnerability (CVE-2014-3566), it is important to exclude the 
SSLv3 protocol (and earlier protocols). The capability to exclude unwanted SSL/TLS protocols from your Apache CXF endpoints depends on the JBoss Fuse 6.1 patch level, as follows:
			- No patch
- No capability to exclude vulnerable protocols from CXF endpoints (thesecureSocketProtocolattribute is available, but is not effective at restricting the available protocols).
- Rollup 2 Patch 4 (R2P4)
- SSLv3and earlier protocols automatically excluded (hard-coded in the runtime).