Details
-
New Feature
-
Status: Closed (View Workflow)
-
Major
-
Resolution: Fixed
-
None
-
None
Description
TlsSocketPlugin still requests SSLContext.getInstance("TLS") and ConnectionHelper documents TLS 1.1 era defaults. With Java 17, TLS 1.3 and the current JSSE cipher defaults are always present.
- Make TLS 1.3 and 1.2 the default enabledSslProtocolSuites and remove the workarounds for older suites.
- Review the enabledSslCipherSuites defaults and sslMode handling against JDK 17 behaviour, including hostname verification through SSLParameters.setEndpointIdentificationAlgorithm.
- Update the TLS tests and the security documentation accordingly.