<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you all just last in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874683#M171482</link>
    <description>&lt;P&gt;Thank you all just last question&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ssl config can be done only in ASA or can be config any switch or router is it normal to config SSL on switch level actually security officer requirement to config ssl in switches as well screenshot attached for reference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how can i config in switches and&lt;/P&gt;
&lt;P&gt;is it default config in cisco switch IOS mentioned in screenshot because i dont see any SSL config in switches&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2016 14:01:30 GMT</pubDate>
    <dc:creator>OPRoger</dc:creator>
    <dc:date>2016-06-21T14:01:30Z</dc:date>
    <item>
      <title>Why we need SSL and TLS and how to config TLS if already SSL present ?</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874676#M171475</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i don't have any knowledge about SSL and TLS kindly describe. what is the purpose of having ssl and tls in our network&lt;/P&gt;
&lt;P&gt;how can i change config from SSL to TLS with 128 bit length&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874676#M171475</guid>
      <dc:creator>OPRoger</dc:creator>
      <dc:date>2019-03-12T07:54:56Z</dc:date>
    </item>
    <item>
      <title>Hi Akbar,</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874677#M171476</link>
      <description>&lt;P&gt;Hi Akbar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regarding the cipher settings on the ASA you can refer "ssl cipher" section in the below link&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s16.html#pgfId-1724385&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;let me know if you have any further query.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if it helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 13:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874677#M171476</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-06-20T13:44:31Z</dc:date>
    </item>
    <item>
      <title>what is the purpose of having</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874678#M171477</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;what is the purpose of having ssl and tls in our network&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;TLS is the successor of SSL. Today, SSL should not be enabled any more on any device as it has shown too many weaknesses.&lt;/P&gt;
&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;
&lt;DIV class="field-items"&gt;
&lt;DIV class="field-item even" property="content:encoded"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;how can i change config from SSL to TLS with 128 bit length&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;That all depends on the device and software-version you use.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 20 Jun 2016 13:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874678#M171477</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-06-20T13:55:36Z</dc:date>
    </item>
    <item>
      <title>Karsten i am using cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874679#M171478</link>
      <description>&lt;P&gt;Karsten i am using cisco ASA 5520 and 8.3 version&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can somebody tell me how can i configure TLS and remove SSL&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 14:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874679#M171478</guid>
      <dc:creator>OPRoger</dc:creator>
      <dc:date>2016-06-20T14:03:07Z</dc:date>
    </item>
    <item>
      <title>First: I would upgrade to the</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874680#M171479</link>
      <description>&lt;P&gt;First: I would upgrade to the newest 8.4 interims-release or if possible to the newest 9.1 release. In 9.1 you also have more crypto-options to secure your firewall.&lt;/P&gt;
&lt;P&gt;For your release, you should configure&amp;nbsp;the following:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ssl server-version tlsv1-only&lt;BR /&gt;ssl encryption aes128-sha1 aes256-sha1&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 Jun 2016 14:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874680#M171479</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-06-20T14:41:41Z</dc:date>
    </item>
    <item>
      <title>and i didn't find ssl or tls</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874681#M171480</link>
      <description>&lt;P&gt;and i didn't find ssl or tls config in firewall is it related to below configs&lt;/P&gt;
&lt;P&gt;please tell me what is the purpose of below configs.&lt;/P&gt;
&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto dynamic-map outside_dyn_map 20 set pfs group1&lt;BR /&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto isakmp enable outside&lt;BR /&gt;crypto isakmp policy 10&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption 3des&lt;BR /&gt; hash sha&lt;BR /&gt; group 2&lt;BR /&gt; lifetime 86400&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;also i dont have &lt;B class="cBold"&gt;show ssl ciphers&lt;/B&gt; &lt;B class="cBold"&gt; all&lt;/B&gt; command and our security officer says we have weak cipher config as mentioned in screenshot&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 09:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874681#M171480</guid>
      <dc:creator>OPRoger</dc:creator>
      <dc:date>2016-06-21T09:51:54Z</dc:date>
    </item>
    <item>
      <title>The config only relates to</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874682#M171481</link>
      <description>&lt;P&gt;The config only relates to IPsec VPNs. And on your platform, you won't get rid of the weak ciphers completely. But they can be&amp;nbsp;reduced with the mentioned config. The "ssl cipher" command is not available on your device. If you need more security, you have to upgrade to an actual platform with a newer software-release. The 5520 is nearly EOL and won't get any actual crypto in the future.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 11:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874682#M171481</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-06-21T11:42:22Z</dc:date>
    </item>
    <item>
      <title>Thank you all just last</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874683#M171482</link>
      <description>&lt;P&gt;Thank you all just last question&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ssl config can be done only in ASA or can be config any switch or router is it normal to config SSL on switch level actually security officer requirement to config ssl in switches as well screenshot attached for reference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how can i config in switches and&lt;/P&gt;
&lt;P&gt;is it default config in cisco switch IOS mentioned in screenshot because i dont see any SSL config in switches&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 14:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874683#M171482</guid>
      <dc:creator>OPRoger</dc:creator>
      <dc:date>2016-06-21T14:01:30Z</dc:date>
    </item>
    <item>
      <title>If you need to enable the</title>
      <link>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874684#M171483</link>
      <description>&lt;P&gt;If you need to enable the webserver on your switches/router, then you need to configure also these devices accordingly. For both platforms you need very new IOS releases to have the tools available to configure that.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 15:40:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-we-need-ssl-and-tls-and-how-to-config-tls-if-already-ssl/m-p/2874684#M171483</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-06-21T15:40:57Z</dc:date>
    </item>
  </channel>
</rss>

