为Oracle HTTP Server(OHS)禁用HTTP

时间:2019-07-08 10:02:19

标签: apache sslv3 oracle-http-server sslv2

为了修复Oracle HTTP服务器上托管的应用程序之一的SSL V2和SSL V3漏洞,我进行了以下更改,但仍可以使用旧的HTTP服务器使用端口7777以及端口4443上的HTTPS访问该应用程序。该端口7777上的HTTP访问应该已经停止,但是没有停止。

1)使用orapki创建了一个新钱包
2)创建CSR以生成签名证书
3)将签名证书导入钱包
4)在opmn.xml中将Sending message: {"temperature": 23.46,"humidity": 64.09} Error: Time:Mon Jul 8 10:48:16 2019 File:C:\Release\iot-sdks-internals\release\python\automation\aziotsdk_pytools\src\c \c-utility\adapters\socketio_win32.c Func:connect_socket Line:261 Failure: connect failure 10060. Error: Time:Mon Jul 8 10:48:16 2019 File:C:\Release\iot-sdks-internals\release\python\automation\aziotsdk_pytools\src\c \c-utility\adapters\socketio_win32.c Func:socketio_open Line:390 lookup_address_and_connect_socket failed Error: Time:Mon Jul 8 10:48:16 2019 File:C:\Release\iot-sdks-internals\release\python\automation\aziotsdk_pytools\src\c \c-utility\adapters\tlsio_schannel.c Func:tlsio_schannel_open Line:1248 xio_open failed Error: Time:Mon Jul 8 10:48:16 2019 File:C:\Release\iot-sdks-internals\release\python\automation\aziotsdk_pytools\src\c \umqtt\src\mqtt_client.c Func:mqtt_client_connect Line:1001 Error: io_open failed Error: Time:Mon Jul 8 10:48:16 2019 File:C:\Release\iot-sdks-internals\release\python\automation\aziotsdk_pytools\src\c \iothub_client\src\iothubtransport_mqtt_common.c Func:SendMqttConnectMsg Line:2151 failure connecting to address testpyt honhub.azure-devices.net. 更改为<data id="start-mode" value="ssl-disabled"/>
5)将ssl.conf更改为以下值

<data id="start-mode" value="ssl-enabled"/>
  <VirtualHost *:4443> #OHS_SSL_VH
   <IfModule ossl_module>
   SSLEngine on
  SSLProtocol All -SSLv2 -SSLv3
   SSLCipherSuite ECDHE:!NULL:!3DES:!RC4:+aRSA:AES128-SHA
   #Path to the wallet

请提供您为什么仍然可以通过端口7777上的http访问我的应用程序的信息吗?

致谢,
桑迪普

0 个答案:

没有答案