IBM webMethods Hybrid Integration

IBM webMethods Hybrid Integration

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

RFC5746 and wM 6.5 IS

  • 1.  RFC5746 and wM 6.5 IS

    Posted Fri August 27, 2010 08:56 AM

    Hi i am administrating wM in our company, and one of our business partners asks about RFC5746 - [url]http://tools.ietf.org/html/rfc5746[/url]

    basically:
    It seams that you require us to send SCSV for signaling in the TLS Client Hello packet, the recommended way to initialize the SSL session is to send TLS Renego extension in TLS Client Hello according tro RFC5746

    and

    What signal mechanism we use… ( TLS Renego extension in TLS Client Hello ) or ( SCSV for signaling in TLS Client Hello packet )

    I just took over, but cant find much on this matters online and internally. A windows patch for this MS10-049 was released… Does wM set up the SSL connections using the OS? or Java? bit lost here


    #webmethods-Protocol-and-Transport
    #Integration-Server-and-ESB
    #webMethods


  • 2.  RE: RFC5746 and wM 6.5 IS

    Posted Wed August 31, 2011 09:29 AM

    Due to a security issue with the TSL/SSL protocol not properly associating renegotiation handshakes with an existing connection - the webMethods integration server is not configured to allow SSL renegotiation by default.

    A Microsoft security update (KB980436 - see [url]http://support.microsoft.com/kb/980436/en[/url] ) complying with the following standard: IETF RFC5746 ([url]http://tools.ietf.org/html/rfc5746[/url]) forces the client to try to use TLS renegotiation…

    solution is to get client to uninstall this patch or install WM fix 23 in where enabling this is a setting in extended settings


    #webMethods
    #Integration-Server-and-ESB
    #webmethods-Protocol-and-Transport