<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ssl-to-tls/m-p/2894833#M172254</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, the ASA supports tlsv1 in your current version. You can mention the client-version and server-version as tslv1 so that you do not hit the POODLE vulnerability.&lt;/P&gt;
&lt;P&gt;Regarding the cipher settings on the ASA you can refer "ssl cipher" section in the below link&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s16.html#pgfId-1724385&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2016 16:23:26 GMT</pubDate>
    <dc:creator>Shivapramod M</dc:creator>
    <dc:date>2016-02-23T16:23:26Z</dc:date>
    <item>
      <title>ASA ssl to tls</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssl-to-tls/m-p/2894832#M172253</link>
      <description>&lt;P&gt;Hi guys. I have a recommendation to switch from SSLv2 to SSLv3 , but I see there is bug at SSLv3 poodle bug. And Cisco recommend to disable sslv3 and enable tlsv1 .&lt;/P&gt;
&lt;P&gt;on my ASA , version 9.2.3.4&lt;/P&gt;
&lt;P&gt;"show ssl"&lt;/P&gt;
&lt;P&gt;1 Accept connections using SSLv2 or greater and negotiate to TLSv1&lt;BR /&gt;2 Start connections using TLSv1 only and negotiate to TLSv1 only&lt;BR /&gt;3 Enabled cipher order: rc4-sha1 dhe-aes128-sha1 dhe-aes256-sha1 aes128-sha1 aes256-sha1 3des-sha1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-does line 1 and 2 mean that ASA already works with TLS instead of SSL ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-if yes do i need still to switch to sslv3 and then do&amp;nbsp;&lt;SPAN&gt;ASA(config)# ssl client-version tlsv1-only &amp;nbsp;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;How can i leave only&amp;nbsp;&lt;SPAN style="font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif;"&gt;AES 256-SHA1 encryption?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thank you&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssl-to-tls/m-p/2894832#M172253</guid>
      <dc:creator>Bekzod Fakhriddinov</dc:creator>
      <dc:date>2019-03-12T07:23:26Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssl-to-tls/m-p/2894833#M172254</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, the ASA supports tlsv1 in your current version. You can mention the client-version and server-version as tslv1 so that you do not hit the POODLE vulnerability.&lt;/P&gt;
&lt;P&gt;Regarding the cipher settings on the ASA you can refer "ssl cipher" section in the below link&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s16.html#pgfId-1724385&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 16:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssl-to-tls/m-p/2894833#M172254</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2016-02-23T16:23:26Z</dc:date>
    </item>
    <item>
      <title>Thank you Shivapramod . But</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssl-to-tls/m-p/2894834#M172255</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you Shivapramod . But from your post its not clear :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;do i need still to switch to SSLv3 and then do&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ASA(config)# ssl client-version tlsv1-only &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ssl server-version tlsv1-only&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt; or not ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 20:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssl-to-tls/m-p/2894834#M172255</guid>
      <dc:creator>Bekzod Fakhriddinov</dc:creator>
      <dc:date>2016-02-23T20:35:45Z</dc:date>
    </item>
  </channel>
</rss>

