security notice and clarifications on choosing the right cipher suite for client key
… for client key (#1591)
magwas authored and davecramer committed Nov 12, 2019
1 parent 5e48eaa commit c67b0b0b667a6b9f1b13ed5359687f3bc20ac61b
@@ -134,6 +134,12 @@ Connection conn = DriverManager.getConnection(url);

`openssl pkcs8 -topk8 -inform PEM -in my.key -outform DER -out my.key.der -v1 PBE-MD5-DES`

*Note:* The use of -v1 PBE-MD5-DES might be inadequate in environments where high level of security is needed and the key is not protected
by other means (e.g. access control of the OS), or the key file is transmitted in untrusted channels.
We are depending on the cryptography providers provided by the java runtime. The solution documented here is known to work at
the time of writing. If you have stricter security needs, please see
for a discussion of the problem and information on choosing a better cipher suite.

* **sslrootcert** = String

File name of the SSL root certificate. Defaults to defaultdir/root.crt

