You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@qpid.apache.org by "Andrew Stitcher (JIRA)" <ji...@apache.org> on 2019/04/01 20:17:01 UTC

[jira] [Resolved] (PROTON-2014) [c] Example broker can silently use anonymous ciphers when misconfigured

     [ https://issues.apache.org/jira/browse/PROTON-2014?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Andrew Stitcher resolved PROTON-2014.
-------------------------------------
       Resolution: Fixed
    Fix Version/s: proton-c-0.28.0

> [c] Example broker can silently use anonymous ciphers when misconfigured
> ------------------------------------------------------------------------
>
>                 Key: PROTON-2014
>                 URL: https://issues.apache.org/jira/browse/PROTON-2014
>             Project: Qpid Proton
>          Issue Type: Bug
>            Reporter: Andrew Stitcher
>            Assignee: Andrew Stitcher
>            Priority: Major
>             Fix For: proton-c-0.28.0
>
>
> The example broker does not check the return value from {color:#2e3436}pn_ssl_domain_set_credentials(){color} and if given a bad certificate will allow anonymous ciphers without even displaying an error message.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@qpid.apache.org
For additional commands, e-mail: dev-help@qpid.apache.org