Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: How can i activate TLS 1.1+ on SAP AS JAVA 7.31 client-side?

$
0
0

Hi Matthias,

I don't know if my answer ist still of some value but I think I should add what I found out.

 

What I am writing here was clarified in an incident with SAP development (BC-JAS-SEC-CPG) which is still not closed.

 

Configuring ssl/client_ciphersuites on an AS JAVA does not influence it's behaviour as an HTTP client in any kind of way. Documentation is ambiguous.

 

TLS client behaviour is provided by iaik JAVA libraries. These libraries currently do not support TLS 1.2 in any NetWeaver release.

 

Our problem is that we have an SaaS partner who wants to deactivate everything older than TLS 1.2 on their servers for security considerations and german BSI compliance.

Today our PI does clearly not support TLS 1.2 when connecting to this service.

 

SAP promised to deliver new libraries with TLS 1.2 support. But they did not deliver for months now.

SAP also was not able or willing to explain how to disable insecure ciphersuites like RC4 on newer 7.X systems. (I know how to do it on 7.0X systems using good old Visual Administrator).

 

We would appreciate your support. Just file an incident to BC-JAS-SEC-CPG.

Regards, Lutz


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>