cancel
Showing results for 
Search instead for 
Did you mean: 

BI Platform Support Tool Issue: question regarding validity of WebApplication System Alert (webapplicationservers.protocolprops.compression)

joshua_kuhn
Employee
Employee
0 Kudos

<posted on behalf of customer>


Alert Summary -> System Alerts -> webapplicationservers.protocolprops.compression


As far as I know enabling compression is controversial, at least for HTTPS. Please see CRIME for details.

Is it recommended by SAP to enable compression also for HTTPS, despite the risks?


Otherwise the corresponding check should be adapted to reflect this.

Accepted Solutions (1)

Accepted Solutions (1)

joshua_kuhn
Employee
Employee
0 Kudos

Alert Summary -> System Alerts -> webapplicationservers.protocolprops.compression

I created a JIRA ticket to review this one. ( BITBITOOL-748 )  We'll work with the internal SAP team that supports the various application servers to get their thoughts on this.  But its quite possible, as you mentioned, we just need to add an SSL check during the evaluation of this alert.

Answers (2)

Answers (2)

Toby_Johnston
Advisor
Advisor
0 Kudos

Hi Mortiz,

I haven't forgotten about this.  I'm waiting for an official statement from the BI product team regarding CRIME and BREACH exploits.  I'll post back again as soon as possible.

Thanks

Toby

former_member196781
Participant
0 Kudos

Hi Toby,

I was just thinking about this yesterday
OK, Thanks!

Best Regards

Moritz

Toby_Johnston
Advisor
Advisor
0 Kudos

I am checking on this with our security team and will follow up asap