When looking at PCAP traces of Java TLS handshake, I can see details in Client Hello like this:
Signature Algorithm: SHA224 DSA (0x0302)
I would like to disable it, so server application does not offer it to the client. As far as I understand, this can be done in JAVA_HOME/conf/java.security
There is already an entry like this:
jdk.tls.disabledAlgorithms=SSLv3, TLSv1, TLSv1.1, DTLSv1.0, RC4, DES, \
MD5withRSA, DH keySize < 1024, EC keySize < 224, 3DES_EDE_CBC, anon, NULL, \
ECDH, TLS_RSA_*, rsa_pkcs1_sha1 usage HandshakeSignature, \
ecdsa_sha1 usage HandshakeSignature, dsa_sha1 usage HandshakeSignature
Is this the right place and what is needed to be entered here, to achive this?