<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5585 ECDHE cipher support? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3229814#M1010994</link>
    <description>&lt;P&gt;Does the ASA 5585 support ECDHE ciphers like ECDHE-RSA-AES256-GCM-SHA384?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I get error message trying to enable them, and I don't see them available:&lt;/P&gt;
&lt;PRE&gt;sho ssl ciphers all
These are the ciphers for the given cipher level; not all ciphers
are supported by all versions of SSL/TLS.
These names can be used to create a custom cipher list
  DHE-RSA-AES256-SHA256 (tlsv1.2)
  AES256-SHA256 (tlsv1.2)
  DHE-RSA-AES128-SHA256 (tlsv1.2)
  AES128-SHA256 (tlsv1.2)
  DHE-RSA-AES256-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  AES256-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  DHE-RSA-AES128-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  AES128-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  DES-CBC3-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  RC4-SHA (tlsv1)
  RC4-MD5 (tlsv1)
  DES-CBC-SHA (tlsv1)
  NULL-SHA (tlsv1)


&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Cisco Adaptive Security Appliance Software Version 9.4(4)8
Device Manager Version 7.6(1)

Compiled on Sun 16-Jul-17 23:27 PDT by builders
System image file is "disk0:/asa944-8-smp-k8.bin"
Config file at boot was "startup-config"

fwt1-asa5585-01 up 123 days 21 hours
failover cluster up 124 days 0 hours

Hardware:   ASA5585-SSP-40, 12288 MB RAM, CPU Xeon 5500 series 2133 MHz, 2 CPUs (16 cores)
Internal ATA Compact Flash, 2048MB
BIOS Flash M25P32 @ 0x0, 4096KB

Encryption hardware device : Cisco ASA-5585 on-board accelerator (revision 0x1)
                             Boot microcode        : CNPx-MC-BOOT-2.00
                             SSL/IKE microcode     : CNPx-MC-SSL-SB-PLUS-0005
                             IPSec microcode       : CNPx-MC-IPSEC-MAIN-0026
                             Number of accelerators: 3

Programmable device : Cisco CPLD revision 0x8&lt;/PRE&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:56:11 GMT</pubDate>
    <dc:creator>jmorrison_bcp</dc:creator>
    <dc:date>2020-02-21T14:56:11Z</dc:date>
    <item>
      <title>ASA 5585 ECDHE cipher support?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3229814#M1010994</link>
      <description>&lt;P&gt;Does the ASA 5585 support ECDHE ciphers like ECDHE-RSA-AES256-GCM-SHA384?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I get error message trying to enable them, and I don't see them available:&lt;/P&gt;
&lt;PRE&gt;sho ssl ciphers all
These are the ciphers for the given cipher level; not all ciphers
are supported by all versions of SSL/TLS.
These names can be used to create a custom cipher list
  DHE-RSA-AES256-SHA256 (tlsv1.2)
  AES256-SHA256 (tlsv1.2)
  DHE-RSA-AES128-SHA256 (tlsv1.2)
  AES128-SHA256 (tlsv1.2)
  DHE-RSA-AES256-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  AES256-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  DHE-RSA-AES128-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  AES128-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  DES-CBC3-SHA (tlsv1, tlsv1.1, dtlsv1, tlsv1.2)
  RC4-SHA (tlsv1)
  RC4-MD5 (tlsv1)
  DES-CBC-SHA (tlsv1)
  NULL-SHA (tlsv1)


&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Cisco Adaptive Security Appliance Software Version 9.4(4)8
Device Manager Version 7.6(1)

Compiled on Sun 16-Jul-17 23:27 PDT by builders
System image file is "disk0:/asa944-8-smp-k8.bin"
Config file at boot was "startup-config"

fwt1-asa5585-01 up 123 days 21 hours
failover cluster up 124 days 0 hours

Hardware:   ASA5585-SSP-40, 12288 MB RAM, CPU Xeon 5500 series 2133 MHz, 2 CPUs (16 cores)
Internal ATA Compact Flash, 2048MB
BIOS Flash M25P32 @ 0x0, 4096KB

Encryption hardware device : Cisco ASA-5585 on-board accelerator (revision 0x1)
                             Boot microcode        : CNPx-MC-BOOT-2.00
                             SSL/IKE microcode     : CNPx-MC-SSL-SB-PLUS-0005
                             IPSec microcode       : CNPx-MC-IPSEC-MAIN-0026
                             Number of accelerators: 3

Programmable device : Cisco CPLD revision 0x8&lt;/PRE&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:56:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3229814#M1010994</guid>
      <dc:creator>jmorrison_bcp</dc:creator>
      <dc:date>2020-02-21T14:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5585 ECDHE cipher support?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3229846#M1010998</link>
      <description>&lt;P&gt;These ciphers were added in 9.4(1), but they are not active when the AnyConnect Essentials license is applied. Is that the case for your&amp;nbsp;ASA?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 22:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3229846#M1010998</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-12-10T22:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5585 ECDHE cipher support?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3297001#M1011001</link>
      <description>&lt;P&gt;Yes, anyconnect essentials is active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So anyconnect disables it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks bad on SSL scans mainly.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 18:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3297001#M1011001</guid>
      <dc:creator>JOHN PAUL MORRISON</dc:creator>
      <dc:date>2017-12-15T18:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5585 ECDHE cipher support?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3297005#M1011002</link>
      <description>&lt;P&gt;Yes, but&amp;nbsp;you should have AnyConnect PLUS licenses. Then you can replace your AnyConnect Essentials with AnyConnect PLUS. With just disabling it you lose your VPN-capabilities.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 18:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/3297005#M1011002</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-12-15T18:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5585 ECDHE cipher support?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/4260170#M1076749</link>
      <description>&lt;P&gt;I know it's been three years but hoping you can still respond. I'm wondering whether to get the Anyconnect Plus or Apex license. According to the Anyconnect ordering guide, Suite B encryption algorithms are only supported in the Apex license. I don't see this listed for the Anyconnect Plus license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/anyconnect-og.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/anyconnect-og.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or does this mean the ciphers will be available in the "show ssl ciphers" but not usable with Anyconnect when using the Plus license?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 15:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-ecdhe-cipher-support/m-p/4260170#M1076749</guid>
      <dc:creator>ptchuba</dc:creator>
      <dc:date>2020-12-17T15:41:34Z</dc:date>
    </item>
  </channel>
</rss>

