2013년 3월 11일 월요일

[TechNote] PM72915: TLS compression should be disabled by default in IHS

PM72915: TLS compression should be disabled by default in IHS

Abstract

IHS V8R0 and later inadvertently enables TLS Compression by default

Download Description

PM72915 resolves the following problem:
ERROR DESCRIPTION:
TLS Compression is enabled by default in V8R0 and later, but there is no integration with commonly used compression at the HTTP level.
USERS AFFECTED:
Users of IBM HTTP Server (IHS) V8R0 and later with SSL enabled on distributed platforms. z/OS is not affected.
PROBLEM DESCRIPTION:
TLS Compression was added to GSKit version 8, but there is no
reason to enable this support in IBM HTTP Server which already
has application layer compression support.
The different layers of compression are not aware of each other
and cause unnecessary CPU.

RECOMMENDATION:
Apply this fix if using SSL with IBM HTTP Server.

PROBLEM CONCLUSION:
IHS was updated to properly disable TLS Compression by default.
TLS Compression can be re-enabled by setting the "SSLCompression
directive to "ON".

This fix is targeted for IHS fixpacks:
- 8.0.0.5
- 8.5.0.1

Note: This interim fix can also be installed using Install Manager (IM) with the
Web-based ("live") repository provided by IBM.

Prerequisites

None

Installation Instructions

Please review the readme.txt for detailed installation instructions

댓글 없음:

댓글 쓰기