<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSR1000v_CRYPTO_OPSSL: SSL3.0 is no longer supported.Enabling only TLS1.0 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4089070#M1070358</link>
    <description>&lt;P&gt;Sure , I will see if they can support Lab router as it's testing purpose before we go with BYOL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did factory-reset and reconfigured it. AnyconnectwAnyconnect with local credentials and same error recurred after we modified authentication method list to use LDAP group first .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Durga Prasad&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2020 03:57:46 GMT</pubDate>
    <dc:creator>NDP</dc:creator>
    <dc:date>2020-05-20T03:57:46Z</dc:date>
    <item>
      <title>CSR1000v_CRYPTO_OPSSL: SSL3.0 is no longer supported.Enabling only TLS1.0</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4088650#M1070340</link>
      <description>&lt;P&gt;recently setup anyconnect on CSR1000v and it worked with local credentials .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of sudden, Anyconnect VPN is no longer working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;CRYPTO_OPSSL: SSL3.0 is no longer supported.Enabling only TLS1.0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;CRYPTO_OPSSL: Set cipher specs to mask 0x00002080 for version 16&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;CRYPTO_OPSSL: Common Criteria is disabled on this session.Disabling Common Criteria mode functionality in CiscoSSL on SSL CTX 0x7F6C7DDB9850&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Those kind of logs I noticed when I did debug for ssl . I do see logs that user credentials are validated and success. but, session got closed automatically.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;show version:-&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;&lt;SPAN&gt;Cisco IOS XE Software, Version 16.12.01a&lt;BR /&gt;Cisco IOS Software [Gibraltar], Virtual XE Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 16.12.1a, RELEASE SOFTWARE (fc2)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could someone how can this be fixed . Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 13:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4088650#M1070340</guid>
      <dc:creator>NDP</dc:creator>
      <dc:date>2020-05-19T13:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v_CRYPTO_OPSSL: SSL3.0 is no longer supported.Enabling only TLS1.0</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4088808#M1070346</link>
      <description>&lt;P&gt;What version of AnyConnect are your clients using?&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 17:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4088808#M1070346</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-05-19T17:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v_CRYPTO_OPSSL: SSL3.0 is no longer supported.Enabling only TLS1.0</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4088823#M1070347</link>
      <description>&lt;P&gt;Hi Marvin,T&lt;SPAN&gt;hank you&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyconnect version is 4.7.04056&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had configured everything as stated in the link :-&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/configure-sslvpn-on-cisco-cloud-services-router-1000v-csr1000v/ta-p/3156679" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/configure-sslvpn-on-cisco-cloud-services-router-1000v-csr1000v/ta-p/3156679&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It worked good with local credentials. It all started after I executed following changes:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working good with the following :-&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;aaa authentication login &lt;FONT color="#339966"&gt;sslvpn&lt;/FONT&gt; local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;aaa authorization exec default local &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;aaa authorization network &lt;FONT color="#339966"&gt;anyconnectvpn&lt;/FONT&gt; local&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;crypto ssl profile anyconnect-profile&lt;BR /&gt;match policy anyconnect-policy&lt;BR /&gt;aaa authentication user-pass list &lt;FONT color="#339966"&gt;sslvpn&lt;/FONT&gt;&lt;BR /&gt;aaa authorization group user-pass list&lt;FONT color="#339966"&gt; anyconnectvpn&lt;/FONT&gt; anyconnect-auth-policy&lt;BR /&gt;authentication remote user-pass &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;changes performed:-&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ldap attribute-map ldap-username-map&lt;BR /&gt;map type sAMAccountName username&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l&lt;FONT color="#339966"&gt;dap server &amp;lt;Server1&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;ipv4 &amp;lt;internalIP&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;attribute map ldap-username-map&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;bind authenticate root-dn CN=Username,OU=XXX,DC=XXX,DC=XXX password&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;base-dn dc=XXX,dc=XXX&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;search-type nested&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;aaa group server ldap &amp;lt;servergroup&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;server server1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;aaa authentication login sslvpn group&amp;nbsp;&amp;lt;servergroup&amp;gt; local&amp;nbsp; &amp;nbsp;--&amp;gt; added group servergroup to authenticate using LDAP&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as soon as We did this, authnetication success logs in debug messages. But, above reported logs and No valid certification authentication error at times on ANyconnect client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 17:31:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4088823#M1070347</guid>
      <dc:creator>NDP</dc:creator>
      <dc:date>2020-05-19T17:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v_CRYPTO_OPSSL: SSL3.0 is no longer supported.Enabling only TLS1.0</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4089061#M1070357</link>
      <description>&lt;P&gt;I don't see why those command would have had that effect. Unless somebody else can offer more insight, you might be best advised to open a TAC case.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 03:33:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4089061#M1070357</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-05-20T03:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v_CRYPTO_OPSSL: SSL3.0 is no longer supported.Enabling only TLS1.0</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4089070#M1070358</link>
      <description>&lt;P&gt;Sure , I will see if they can support Lab router as it's testing purpose before we go with BYOL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did factory-reset and reconfigured it. AnyconnectwAnyconnect with local credentials and same error recurred after we modified authentication method list to use LDAP group first .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Durga Prasad&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 03:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-crypto-opssl-ssl3-0-is-no-longer-supported-enabling/m-p/4089070#M1070358</guid>
      <dc:creator>NDP</dc:creator>
      <dc:date>2020-05-20T03:57:46Z</dc:date>
    </item>
  </channel>
</rss>

