<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL v3 POODLE vulnerablity in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/ssl-v3-poodle-vulnerablity/m-p/349818#M13458</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5;"&gt;From the ESRI blog:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;MAJOR UPDATE 10/24/14&lt;/STRONG&gt; – On October 14, 2014, a security vulnerability involving SSL v3 was revealed called POODLE (&lt;A href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566" style="color: #007ac2; background: transparent;"&gt;&lt;SPAN style="color: #0563c1; background: transparent;"&gt;CVE-2014-3566&lt;/SPAN&gt;&lt;/A&gt;).&amp;nbsp; SSL v3 is estimated to be utilized by less than 2% of Internet users at this time, many of those users have browsers as old as IE6 (which is not supported across most products, and does not support the TLS protocol).&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;ArcGIS Online:&lt;/STRONG&gt; Esri has disabled SSL v3 for all ArcGIS Online web service endpoints and is not vulnerable to POODLE attacks.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;ArcGIS Server &amp;amp; Portal for ArcGIS:&lt;/STRONG&gt; Current versions of these products handle HTTPS requests that allow fallback to SSL v3; however&lt;A href="http://resources.arcgis.com/en/help/main/10.2/#/Deployment_scenarios/015400000488000000/" style="color: #007ac2; background: transparent;"&gt;&lt;SPAN style="color: #0563c1; background: transparent;"&gt;Esri recommends&lt;/SPAN&gt;&lt;/A&gt; that production implementations include the ArcGIS web adaptor in front of them to terminate encrypted connections with clients based on the web server it is deployed to.&amp;nbsp; Each web server vendor has specific guidance for how to disable SSL v3 with their products.&amp;nbsp; For your convenience we have provided links to some of the common web servers utilized in the references section below.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;Browsers:&lt;/STRONG&gt; The POODLE vulnerability requires that both servers and browsers have SSL v3 enabled.&amp;nbsp; As a security precaution beyond our products, we recommend customers disable SSLv3 within their browser settings where it is possible for them to do so.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;Future Builds:&lt;/STRONG&gt; &lt;SPAN style="color: #e23d39;"&gt;&lt;STRONG&gt;Esri has already disabled SSL v3&lt;/STRONG&gt; &lt;/SPAN&gt;for the upcoming ArcGIS 10.3 release.&amp;nbsp; All browser versions supported with the ArcGIS Platform support TLS, and will work without issue.&amp;nbsp; All versions of Python included with the ArcGIS Platform since 10.0 support TLS, therefore most custom scripts should continue to work.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;EM style="background: transparent;"&gt;- The Security Standards &amp;amp; Architecture Team&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5;"&gt; The part I put in red text is an issue.&amp;nbsp; We've installed the prerelease as an upgrade to one of our 10.2.2 servers and SSL v3 still works just fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5;"&gt;I was able to disable it, however, &lt;SPAN style="color: #e23d39;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;ESRI does not condone nor support modifying the built in Tomcat server&lt;/STRONG&gt;&lt;/SPAN&gt;.&amp;nbsp; For those of you wishing to chance it like me, here are the instructions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;Open &amp;lt;install directory&amp;gt;\ArcGIS\Server\framework\runtime\tomcat\conf\server.xml in a text editor&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;Find the line that begins with "&amp;lt;Connector SSLEnabled="true"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;In that line, replace &lt;STRONG&gt;sslProtocols="TLS&lt;/STRONG&gt;" with &lt;STRONG&gt;sslEnabledProtocols="TLSv1, TLSv1.1, TSLv1.2"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;Restart ArcGIS Server&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Nov 2014 19:29:35 GMT</pubDate>
    <dc:creator>ScottNoldy</dc:creator>
    <dc:date>2014-11-21T19:29:35Z</dc:date>
    <item>
      <title>SSL v3 POODLE vulnerablity</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/ssl-v3-poodle-vulnerablity/m-p/349818#M13458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5;"&gt;From the ESRI blog:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;MAJOR UPDATE 10/24/14&lt;/STRONG&gt; – On October 14, 2014, a security vulnerability involving SSL v3 was revealed called POODLE (&lt;A href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566" style="color: #007ac2; background: transparent;"&gt;&lt;SPAN style="color: #0563c1; background: transparent;"&gt;CVE-2014-3566&lt;/SPAN&gt;&lt;/A&gt;).&amp;nbsp; SSL v3 is estimated to be utilized by less than 2% of Internet users at this time, many of those users have browsers as old as IE6 (which is not supported across most products, and does not support the TLS protocol).&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;ArcGIS Online:&lt;/STRONG&gt; Esri has disabled SSL v3 for all ArcGIS Online web service endpoints and is not vulnerable to POODLE attacks.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;ArcGIS Server &amp;amp; Portal for ArcGIS:&lt;/STRONG&gt; Current versions of these products handle HTTPS requests that allow fallback to SSL v3; however&lt;A href="http://resources.arcgis.com/en/help/main/10.2/#/Deployment_scenarios/015400000488000000/" style="color: #007ac2; background: transparent;"&gt;&lt;SPAN style="color: #0563c1; background: transparent;"&gt;Esri recommends&lt;/SPAN&gt;&lt;/A&gt; that production implementations include the ArcGIS web adaptor in front of them to terminate encrypted connections with clients based on the web server it is deployed to.&amp;nbsp; Each web server vendor has specific guidance for how to disable SSL v3 with their products.&amp;nbsp; For your convenience we have provided links to some of the common web servers utilized in the references section below.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;Browsers:&lt;/STRONG&gt; The POODLE vulnerability requires that both servers and browsers have SSL v3 enabled.&amp;nbsp; As a security precaution beyond our products, we recommend customers disable SSLv3 within their browser settings where it is possible for them to do so.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;STRONG style="background: transparent;"&gt;Future Builds:&lt;/STRONG&gt; &lt;SPAN style="color: #e23d39;"&gt;&lt;STRONG&gt;Esri has already disabled SSL v3&lt;/STRONG&gt; &lt;/SPAN&gt;for the upcoming ArcGIS 10.3 release.&amp;nbsp; All browser versions supported with the ArcGIS Platform support TLS, and will work without issue.&amp;nbsp; All versions of Python included with the ArcGIS Platform since 10.0 support TLS, therefore most custom scripts should continue to work.&lt;/P&gt;&lt;P style="margin: 0 0 10px; font-family: Arial, Helvetica, sans-serif; color: #333333; font-size: 14px; background: #ffffff;"&gt;&lt;EM style="background: transparent;"&gt;- The Security Standards &amp;amp; Architecture Team&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5;"&gt; The part I put in red text is an issue.&amp;nbsp; We've installed the prerelease as an upgrade to one of our 10.2.2 servers and SSL v3 still works just fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5;"&gt;I was able to disable it, however, &lt;SPAN style="color: #e23d39;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;ESRI does not condone nor support modifying the built in Tomcat server&lt;/STRONG&gt;&lt;/SPAN&gt;.&amp;nbsp; For those of you wishing to chance it like me, here are the instructions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;Open &amp;lt;install directory&amp;gt;\ArcGIS\Server\framework\runtime\tomcat\conf\server.xml in a text editor&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;Find the line that begins with "&amp;lt;Connector SSLEnabled="true"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;In that line, replace &lt;STRONG&gt;sslProtocols="TLS&lt;/STRONG&gt;" with &lt;STRONG&gt;sslEnabledProtocols="TLSv1, TLSv1.1, TSLv1.2"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="line-height: 1.5;"&gt;Restart ArcGIS Server&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Nov 2014 19:29:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/ssl-v3-poodle-vulnerablity/m-p/349818#M13458</guid>
      <dc:creator>ScottNoldy</dc:creator>
      <dc:date>2014-11-21T19:29:35Z</dc:date>
    </item>
  </channel>
</rss>

