Uploaded image for project: 'Artifactory Binary Repository'
  1. Artifactory Binary Repository
  2. RTFACT-19352

Xray port 8000 offers SSLv3 and TLS1.0 and is not configurable

    Details

    • Type: Bug
    • Status: Open
    • Priority: Normal
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Security, Xray
    • Labels:

      Description

      The default Xray server on port 8000 allows SSLv3 and TLS1.0 (both unsecure nowadays) and there is apparently no place to configure what protocols and ciphers for Xray to use.

      "Use a reverse proxy in front of it" you say – there is also no guidance in the Xray documentation about how to properly configure a reverse proxy in front of Xray to suit Xray's needs.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              jblaine Jeff Blaine
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: