Skip to main content
jdunn_certain
Participant
October 27, 2017
Question

cfhttp in CF11 always sends TLSv1 when using client certificate

  • October 27, 2017
  • 1 reply
  • 413 views

We have our JVM (1.7) set to use TLS1.2 by default, and cfhttp correctly uses that setting, unless we use the clientcert attribute; when the clientcert attribute is used the ClientHello always sends TLSv1. Has anyone else encountered this behavior?

    This topic has been closed for replies.

    1 reply

    BKBK
    Community Expert
    Community Expert
    October 29, 2017

    This sounds eerily like a TLS issue that was discovered in Lucee. There it turned out that "TLSv1" had been hard-coded in the underlying Java library. So, to be on the safe side, you should report this as a bug. It might help to mention the Lucee link in your report.

    jdunn_certain
    Participant
    October 30, 2017

    Thank you BKBK, I have created issue CF-4200073.

    CF-4200073

    CF-4200073