Countermeasures to Neutralize TLS Renegotiation MITM Vulnerability in JAVA
The protocol level TLS renegotiation Man-In-The-Middle (MITM) vulnerability has already been fully fixed in Java SE for quite a while. The following table shows the status of JDK/JRE releases and updates to neutralize the vulnerability in Java. Renegotiation is Vulnerable Renegotiation is Disabled Renegotiation is Secure JDK/JRE 7 N/A N/A All releases JDK/JRE 6 Update 18 and earlier Updates 19-21 Update 22 JDK/JRE 5.0 Update 23 and earlier Updates 24-25 Update 26 JDK/JRE 1.4.2 Update 25 and earlier Updates 26-27 Update 28 Unfortunately, research shows many famous commercial sites on the Web have not yet upgraded their software, according to the last report, Potential Vulnerability status of major ecommerce sites (Please see my previous post ). Much worse, for some circumstance, it is not always easy to upgrade Java Runtime Environment. In such cases, we need workarounds to mitigate the impact of the vulnerability on vulnerable releases. T he Primary Countermeasu...