Disabling SSL 3.0 closure alerts in CSM with SSL module?
Hi: I have a CSM with a SSL module. How do I disable the CSM from sending SSL closure alerts to the client?
Also is there a way to increase the amount of time the CSM waits before it send the SSL closure alert. Looks like the default is 14 seconds.
Thanks
Ravi
found my answer: ssl-server 20 unclean-shutdown
Similar Messages
-
How to use debug on CSM SSL module?
I'm installing a new CSM with SSL module (WS-X6066-SLB-S-K9) and can't get the debugs to work. Acutally, I enabled debugging (to troubleshoot SSL Handshake problems) but nothing shows up on the screen or in the log. Any ideas?
mcbconmrk105d1z2-ssl#show debugging
STE Mgr:
STE SSL Pkt debugging is on
STE SSL Handshake events debugging is on
STE SSL Alert events debugging is on
STE SSL detailed debugging is on
STE SSL error events debugging is on
SSL Subsystem:
SSL Handshake Message debugging is on
SSL Traffic debugging is on
SSL Error debugging is on
SSL Event debugging is on
mcbconmrk105d1z2-ssl#show log
Syslog logging: enabled (0 messages dropped, 31 messages rate-limited, 0 flushes, 0 overruns, xml disabled)
Console logging: level debugging, 254 messages logged, xml disabled
Monitor logging: level debugging, 241 messages logged, xml disabled
Logging to: vty4(0)
Buffer logging: level debugging, 284 messages logged, xml disabled
Logging Exception size (8192 bytes)
Count and timestamp logging messages: disabled
Trap logging: level informational, 324 message lines logged
mcbconmrk105d1z2-ssl#
Thanks in advance,
Danielthe debug messages are displayed on a different console. The console is different depending on the type of debug.
telnet 2001 ? FDU cpu
telnet 2002 ? TCP cpu
telnet 2003 ? SSL cpu
Gilles. -
my Website is hosted on Sun OS 5.06 (OAS 4.0.8) and using web server : Oracle_Web_Listener/4.0.8. Website is configured to use https for secure pages and it was working fine from last 10 years but suddenly i am getting complaints from my customers that they can not browse site on chrome version 40 and above and firefox 34 and above.
I searched for this issue and found that there is POODLE attack which may causing this issue. now the only solution i can see is to disable SSL v3 on server.
Can any help me out with the process or an idea, How to disable SSL V3 on this Olde server? its sun microsystem server.Hi Aamir,
This is old software, been a while since I saw one of these.
Normally when SSL was setup there were two listeners, one with SSL and one without, in a different port, so you could try to find this second port, which may work without any need to change the configuration.
Else, try to check on the OAS manager (Usually on port 8888), the HTTP listener -> WWW -> Network, if there is a setup only for the SSL port, you will need to add a new line, with the same configuration, but a different port and the security disabled.
Also, there may be some setting on the application itself for the url path. If so, when you navigate in the application it will try to redirect you back to the SSL port. In that case you will need to figure out where to change that, which depend on the application itself.
Found this page on google with the process to setup SSL on OAS 4.0, you need to do the inverse of step 5.
WoSign Support: SSL Certificates Installation Instruction - Oracle Web Server (OAS 4.0.8)
Regards,
Luis -
Load Balancing with a CSM & SSL Module
I'm trying to understand the best way to balance traffic to two servers when decrypting and re-encrypting with the CSM and an SSL module. I take the SSL traffic hitting the first CSM VIP and forward to the SSL module for decryption. Send the decrypted traffic back to another VIP on the CSM. Send the traffic to the client proxy VIP on the SSL which encrypts the traffic and forwards to the CSM VIP. That final VIP passes the traffic to the serverfarm containing the actual servers. How do I make sure the traffic is balanced between the final VIP and my servers. It seems that sticking on SSL session ID is the only way to go at that point which made decryption pointless. I feel like I'm missing something basic here.
Thanks..Hi David,
Here find some full config example for your perusal for CSM and SSL Services Module Initial Configuration Example
http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a0080216c16.shtml
2nd config example to Configuring CSM to Load Balance SSL to a Farm of SCAs for One-Armed Proxy Mode
http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00801aca55.shtml
Sachin garg -
Disable SSL 2.0 on Windows 2008 R2
Hi.
Can anyone give me a step by step on how to disable SSL 2.0 on IIS 7.5 please? I cannot find an article for it and those refering to IIS 7.0 do not seem to work.
Regards,
Morris
Best Regards, Morris Fury AFRIDATA.netMorris -
Client-side SSL 2.0 is disabled by default on Windows 7 and Windows Server 2008 R2, which means that, when initiating an SSL connection from either of those two OSes that SSL 2.0 will not be sent as a supported protocol that the server can use. You can see
this in the following registry value:
Key: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Client
Value: DisabledByDefault
Server-side SSL 2.0 is not, however, disabled by default. This means that some other client, when initiating an SSL connection
to Windows Server 2008 R2 can include SSL 2.0 in the list of supported protocols. If SSL 2.0 is the only protocol in common between the client and the server, the server will select it.
Functionally, there is not much difference between setting Enabled to 0 and setting DisabledByDefault to 1.
Hope this helps,
Jonathan Stephens
This posting is provided "AS IS" with no warranties, and confers no rights. Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can
be beneficial to other community members reading the thread. -
HTTPS Keepalive with the CSM & SSL Module
Has anyone had any success getting a secured web page for a keepalive using the CSM with and SSL module. If so can post an example?
Thank you,
DaveHi David,
Here find some full config example for your perusal for CSM and SSL Services Module Initial Configuration Example
http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a0080216c16.shtml
2nd config example to Configuring CSM to Load Balance SSL to a Farm of SCAs for One-Armed Proxy Mode
http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00801aca55.shtml
Sachin garg -
Disabling SSL in Aqualogic Service Registry
Hi All,
i have installed and deployed Aqualogic Service Registry (ALSR) on weblogic server 9.2. However, by default, SSL is enabled during installation. I tried disabling SSL using Weblogic Admin Console but that didn't help. Is there a way i can configure ALSR war to disable SSL?
--VivekHi James,
As I am using ALSR and not OSR and also, deploying it on weblogic server (since, ALSR doesn't support oc4j server), I don't understand why i need to put this question in SOA suite forum.
Installation of ALSR creates registry.war that eventually gets deployed on weblogic server. ALSR doesn't allow me to choose SSL enabling, it choses it by default which is not the case in OSR.
--Vivek -
Disable SSL 3.0 in DSEE 7
Hello,
Is there a way to disable SSL 3.0 in DSEE 7, such that only TLS 1.0/1.1/1.2 can be used? I Googled for this and found MOS document 1950334.1, but the instructions in the document only apply to a DS proxy server.
Thanks,
DaveDisabling SSLv3 by changing the encryption settings but it did not actually work. I loaded the LDIF and restarted the instance, and LDAP indicated that the change took effect:
root@ldap-test:/# ldapsearch -D "cn=Directory Manager" -w xxxxxxxx -b "cn=config" -s sub '(cn=encryption)'
version: 1
dn: cn=encryption,cn=config
objectClass: top
objectClass: nsEncryptionConfig
cn: encryption
nsSSLSessionTimeout: 0
nsSSLClientAuth: allowed
nsSSLServerAuth: cert
nsSSL2: off
nsKeyfile: alias/slapd-key3.db
nsCertfile: alias/slapd-cert8.db
nsSSL3Ciphers: all
nsSSL3: off
However, a test with openssl with the "-ssl3" option (forcing it to only use SSLv3) still connected:
$ /usr/local/openssl-1.0.1k/bin/openssl s_client -connect ldap-test.our-domain.edu:636 -ssl3
CONNECTED(00000003)
... <showed our server certificate, etc.> ...
If SSLv3 were actually disabled, that openssl test would have failed with an error. Disabling SSLv3 is required by our auditing tool because of the POODLE vulnerability, and a system cannot pass our audit unless SSLv2 and SSLv3 are disabled completely, but TLS 1.0/1.1/1.2 are still available. -
Apple Mail 8.2 disables SSL to POP3 server (Securityrisk)
Hi,
Setup
Computer:
OSX 10.10.2
Mail 8.2 (2070.6)
Mail server A
POP3 port 995 SSL
(Non SSL - port 110 - is disabled due to security reasons)
Mail server B
POP3 port 110
POP3 port 995 SSL
Summary
OSX Mail client removes SSL support on non regular intervals for POP3 connections. For the connections that support regular non SSL POP3 (port 110) this reduces the security, but the mail is available. This was noticed by me because one ISP has locked down their POP3 server to SSL only due to security reasons. After reenabling SSL on the connection (Mail -> Preferences -> Accounts -> Account in question -> Advanced) the connection remains with SSL support for a while, then it is removed again. As OS X Mail has no token to identify SSL or regular port 110 connection this is transparant to the user, unless the server does not support regular POP3, at which time a error is generated.
Comments
1) This seems to be a security related issue with mail where OS X mail downgrades from SSL connection to regular port 110 POP3 traffic
2) If corrected the connection is downgraded again within a couple of days, if not sooner.
3) Connections to POP3 servers supporting port 110 are "unaffected" with the exception of the security issue of a downgrade
4) Connections to POP3 servers that only support SSL - port 995 - are not able to complete until SSL has been reenabled manualy.
5) Downgrade bug has been seen only on my machine, so it might not be something mainstream. Machine is updated to latest patches.
Questions
1) As this has only been observed on my machine, has anybody else seen this POP3 SSL downgrade bug?Same problem. The following information is from Symantec:
To disable SSL\TLS
Open Apple Mail.
Click the Mail menu and select Preferences.
Select your mail account on the left under Accounts, then click the Advanced tab.
Confirm the check box labeled "use SSL" is not checked next to ports. If necessary remove the checkmark.
Click the Account Information tab and select Edit Server list from the drop down next to Outgoing Mail Server.
Click the Advanced tab and confirm there is not a checkmark next to Use Secure Socket Layer(SSL).
Click OK and close the accounts. Window and choose to save.
Click Save to update your settings.
Restart Apple Mail.
This does work for a while but eventually Mail reverts to enabling Use SSL and disabling Allow Insecure Authentication but only one some of my addresses but not all. Some accounts POP logs-in but not SMTP. -
RDS 2012 issues after disabling SSL 3.0
Hi all, we have Server 2012 R2 RDS infrastructure. I have 2 servers running RD web, gateway, and conn broker using Windows network load balancing. 3 RDSH servers behind them handling user workload.
Last night I disabled SSL 3.0 on both of these servers using the registry key 'Enabled' set to zero in HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server. Servers were rebooted after this change.
I did not disable SSL 3.0 on the RDSH servers yet, but I don't think it matters in this situation because the SSL traffic only passes between the remote computer and the RDGW server, AFAIK.
Today all the remote users were having issues with remote desktop sessions disconnecting them, but they would reconnect after a short time. They all told me this is unusual, normally the connections are quite stable. After I turned SSL 3.0 back on and rebooted,
no more issues, users are happy. Has anyone else experienced this? Is there anything that can be done to stabilize connections while SSL 3.0 is disabled?Hi,
Thank you for posting in Windows Server Forum.
Did they receive any precise error when SSL3 is disabled?
What’s your client OS and RDP version using for your network?
If you would like to continue with SSL3 disabled you may try to change the RDP Security Layer under Security Layer.
When you are using RD Security Layer you are susceptible to MITM attack because there is no Server Authentication. I suggest you re-enable TLS 1.0 and have a ssl certificate from a public authority set on your RDP-Tcp listener.
You can also refer this article for other information.
Hope it helps!
Thanks.
Dharmesh Solanki
TechNet Community Support -
ILOM, how to disable SSL v2?
Hello
Is there any possibility to disable SSL v2?
I want to use HTTPS to connect to the server (Java Console) but it have to use SSL v3 only. Once trying to connect with v2 of SSL connection should not be established.
Is there any possibility to do this?
SP Firmware Version is: 3.0.3.20.e
SP Filesystem Version 0.1.22
Edited by: Luceks on Sep 2, 2009 4:28 AMHi.
You should have a SSL section under:
1) Log in to the ILOM-SP WEB interface.
2) Click --> Management --> SSL (or similar...)
3)
The SSL page appears. There're some sections to the SSL page.
One section includes targets and properties and you can configure the SSL settings displayed
in this section page (example):
**SSL**
State = Enabled | Disabled
Roles = Administrator | Operator | Advanced | (none)
Address = 0.0.0.0
Port = 0
4) Save settings page, to save any changes made to this section.
s. -
Disable SSL v2 and weak cipers on a RV325 for PCI compliance
How do you disable SSL v2 and weak cipers on a RV325 to become PCI compliant?
Hello
per Cisco RVS4000 product site information this router is already end of life since January 30, 2010. Last date of support is also already missed - April 30, 2013. This means that according Cisco policy no further updates to existing firmware will be done - neither security-related fixes. And I am afraid that this is fact with which you have to deal.
regarding RV320 - it seems that there is no any possibility to restrict SSL/TLS protocol/version by your own in current version. Francis - I would recommend you to open service request to Cisco SMB Support if you still have valid support contract. I hope there is good chance to get it fixed as this security related inability.
lastly - for all products (including RVS4000) - I would suggest to keep management interface of router separated most as possible - i.e. restrict access to management interface only to single subnet/host(s) only (via Firewall feature). With having administration/management subnet and certain client(s) which is a part of this subnet can help to avoid eavesdropping your connection to router. Of course disabling remote management is the best thing you can do in any case (including avoid of possible firmware bugs, loggin attempts and so on). -
Disabling SSL open domain server. How?
Hi all,
Can anybody elicidate to me how I can disable the SLL on a Open Domain OSX server?
In
http://support.apple.com/kb/HT5300
it is explained that you have to disable SSL prior to updating OSX from Mountain Lion with OSX server 2.2 to OSX MAvericks with server 3.
Any help is highly appreciated. Thanks alreadyHi UptimeJeff,
Thanks for the reply.
I have rolled back three times from Mavericks to Mountain Lion server and will now stay there for some month until the quirks are ironed out. Mavericks OSX server is just to cumbersome right now.
So no email log to check at the moment.
But the email archives were not too big and the server had a full good night to do that.
The problem was strictly that server 3 app does not open after download and install and therefore does not let me finish configuration of the server.
Thanks anyway. -
I disabled SSL v3, now a POP3 connection is failing
I disabled SSL v3.0 to protect us from the Poodle vulnerability, now I find a vendor, providing a service deemed as critical, is unable to connect over POP3. It was working until Friday, when SSL v3.0 was disabled in the registry, since then the connection
has been failing. I have deleted the registry key I created to disable this, no change. Any ideas what I need to do to get this working again?
I am using Exchange 2013 on Server 2012 R2Hi,
Disabling the use of SSL v3 on the client will prevent all clients to use SSL v3.0 to establish SSL channels, these will use TLS instead; the consequence of this is for services (applications servers) who don’t support TLS, who only rely
on SSL 3.0 for SSL encryption => clients/browsers without support of SSL v3.0 won’t be able to access services using SSL v3.0 only; they just won’t understand other SSL encryption protocols than SSL v3.0. For more information, please refer to:
Vulnerability in SSL 3.0 – Poodle attack and Exchange 2010 or Exchange 2013
Therefore, only if the application accessing uses only SSL 3.0 would be affected. Please contact your vendor which provide
a service deemed as critical to confirm if it has TLS enabled by default. Then you can change the POP3 connection to use TLS to have a try.
Regards,
Winnie Liang
TechNet Community Support -
Hi all,
i know that SSL version3 by default is enabled on the CSS.
is there anyway to disable SSL version 2 ?
Please Advice
HasanAre you referring to the ssl module ?
Here is what we support on the module :
CSS11503-2(config-ssl-proxy-list[gdufour])# ssl-server 1 version ?
ssl-tls SSL v3 & TLS v1
tls TLS Version 1
ssl SSL Version 3
No ssl version 2.
Gilles.
Maybe you are looking for
-
Right now Task manager Performance tab on Memory says: Total 3958; Cached mem 1588; Avail 2239; Free 722; Physical Mem 43% and this window is the only thing open. Kernel mem (MB) says Paged 179 and Nonpaged 80. I can get you more info if you tell me
-
For some reason I cannot, out of the blue, send an email that contains a PDF attachment. I have shut off my ipad and iphone5 , as this is happening on both, removed and added email accounts, and nothing works.
-
How to position text in an existing PDF document with X,Y coordinates
There used to be a CFX PDF tag that could do this. the company (www.easel2.com) does not appear to exist any more. This is what i want to do. I have an existing PDF file that is uploaded by a user. I want to receive the file, then put a registrati
-
How to get project server in provisioning state?
Hi All, We are working in project server 2013 and integrated it with Microsoft TFS 2010 successfully, but the problem we are getting since two days is we are not able to create or update projects or tasks in project server and Queue is not utilizing
-
Fetching PO data at co code level
Dear, we are using web dynpro application for doing transactions by internal & external users. in one application, when user enters vendor code, system fetches all the PO raised to that vendor. as some user are suppose to do transaction only for one