Has anyone had success disabling TLSv1.0 in Tomcat?
The new PCI DSS 3.1 requirements require that not only SSLv2 and SSLv3 be disabled, but TLSv1.0 as well (leaving only TLSv1.1 and TLSv1.2). This is problematic for the JSS, because disabling TLSv1.0 appears to break connectivity between the jamf binary and the JSS:
Checking availability of https://<JSS>:8443/...
2015-06-08 20:34:36.310 jamf[4097:6966036] CFNetwork SSLHandshake failed (-9824)
2015-06-08 20:34:36.344 jamf[4097:6966036] NSURLConnection/CFURLConnection HTTP load failed (kCFStreamErrorDomainSSL, -9824)
Before I put in a feature request and/or open a support case, has anyone found a combination of non-TLSv1.0 protocols and ciphers that the jamf binary is happy with?
