Securing Bitbucket Server (using Tomcat) against Poodle Disabling SSLv3
Purpose
Disabling SSLV3 in Bitbucket Server instances utilizing a Tomcat container in order to secure against the Poodle Exploit.
How To
Bitbucket Server version 5.+
- Stop Bitbucket Server
Edit
<Bitbucket home directory>
/shared/bitbucket.properties
Add the following to the connector:
server.ssl.enabled=true server.ssl.enabled-protocols=TLSv1.2,TLSv1.1,TLSv1
Start Bitbucket Server
Bitbucket Server up to version 4.x
- Stop Bitbucket Server
Edit
<Bitbucket Home Directory>/shared/server.xml
You'll see:
Please note these are default values, yours may look differentserver.xml<Connector port="8443" maxHttpHeaderSize="8192" SSLEnabled="true" maxThreads="150" minSpareThreads="25" maxSpareThreads="75" enableLookups="false" disableUploadTimeout="true" useBodyEncodingForURI="true" acceptCount="100" scheme="https" secure="true" clientAuth="false" sslProtocol="TLS" />
Add the following to the connector:
SSLEnabled="true" sslEnabledProtocols="TLSv1.2,TLSv1.1,TLSv1"
Start Bitbucket Server
Last modified on May 2, 2017
Powered by Confluence and Scroll Viewport.