-
Type:
Support Request
-
Resolution: Handled by Support
-
Priority:
Low
-
None
-
Affects Version/s: 3.5.4
-
Component/s: None
I understand that Fisheye/Crucible is standalone Java program and therefore the help how to disable SSLv3 for JIRA does not apply here (https://confluence.atlassian.com/display/JIRA/How+To+Disable+SSLv3+to+Mitigate+Against+POODLE+Exploit+for+JIRA).
I tried to run fisheye by adding -Dhttps.protocols=TLSv1 to FISHEYE_OPTS options list (based on suggestions from Oracle: http://www.oracle.com/technetwork/java/javase/documentation/cve-2014-3566-2342133.html) but I can still open Fisheye webpage with browser where sslv3 is enabled. Any other suggestions what I should try?
My environment is Fisheye 3.5.4 running on jdk1.7.0_72