Comment 2 for bug 1058955

Revision history for this message
Jason Gerard DeRose (jderose) wrote : Re: Disabled TLS compression to protect against CRIME like attacks

Interestingly, it's not possible to disable TLS compression under Apache 2.2, something we should keep in mind for our Apache SSL frontend servers:

https://issues.apache.org/bugzilla/show_bug.cgi?id=53219

From testing I've done, I've confirmed you can disabled it from the client-side, so we're covered as far as Microfiber goes. But we also have to worry about the CouchDB replicator.