<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 5510 ssl and ssh in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519093#M615452</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You require to be in configuration mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Dec 2010 19:37:02 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-12-07T19:37:02Z</dc:date>
    <item>
      <title>Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519088#M615439</link>
      <description>&lt;P&gt;Hello everyone, We have user that use credit card vedor services and they are charging us more because according to them we have ssl 2.0 and ssh 1 version and they are security vunerbilities.&amp;nbsp; They say if we upgrade to ssl 3.0 or ssh 2.0 then it would be fine.&amp;nbsp; How do i check which verison i have and how can i change or disable them.&amp;nbsp; Will this effect any of our network(like exhcange owa, etc).&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519088#M615439</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2019-03-11T19:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519089#M615440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To check the SSH version do ''sh run ssh''&lt;/P&gt;&lt;P&gt;To change it ''ssh version [1 | 2]''&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SSL:&lt;/P&gt;&lt;P&gt;ssl server-version ?&lt;/P&gt;&lt;P&gt;ssl client-version ?&lt;/P&gt;&lt;P&gt;To check the current accepted version ''sh cry ssl''&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:18:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519089#M615440</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T19:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519090#M615443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didd "sh run ssh" and it shows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA# sh run ssh&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also doesn't let run ''ssh version [1 | 2]''&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samething for ssl " 'sh cry ssl'' -- it say invalid entry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:31:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519090#M615443</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T19:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519091#M615447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which OS version are you running?&lt;/P&gt;&lt;P&gt;sh version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519091#M615447</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T19:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519092#M615450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA Version 8.0(3)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519092#M615450</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T19:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519093#M615452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You require to be in configuration mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519093#M615452</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T19:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519094#M615454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i did that in config mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519094#M615454</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T19:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519095#M615455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I mentioned that because from your post it shows you're in privilege mode and not in configuration mode.&lt;/P&gt;&lt;P&gt;If you're in configuration mode, what do you get with this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# ssh ?&lt;/P&gt;&lt;P&gt;ASA(config)# ssl ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519095#M615455</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T19:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519096#M615457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA(config)# sh ssh&lt;BR /&gt;Timeout: 60 minutes&lt;BR /&gt;Versions allowed: 1 and 2&lt;BR /&gt;0.0.0.0 0.0.0.0 outside&lt;BR /&gt;0.0.0.0 0.0.0.0 inside&lt;BR /&gt;ASA(config)# sh cry ssl&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;BR /&gt;ASA(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ssh it says both version allowed.&amp;nbsp; How can be disable version 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ssl it's say invalid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:52:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519096#M615457</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T19:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519097#M615458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry forget to include the following info that your requested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# ssh?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;exec mode commands/options:&lt;BR /&gt;&amp;nbsp; ssh&lt;BR /&gt;ASA(config)# ssl?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; ssl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519097#M615458</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T19:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519098#M615459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA(config)# ssh version 2&lt;/P&gt;&lt;P&gt;ASA(config)# sh ssh&lt;/P&gt;&lt;P&gt;Timeout: 30 minutes&lt;BR /&gt;Version allowed: 2&lt;BR /&gt;0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh ssl&lt;/P&gt;&lt;P&gt;Accept connections using SSLv2, SSLv3 or TLSv1 and negotiate to SSLv3 or TLSv1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# ssl server-version ?&lt;BR /&gt;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and either SSLv3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; or TLSv1 will be negotiated&lt;BR /&gt;&amp;nbsp; sslv3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLv3&lt;BR /&gt;&amp;nbsp; sslv3-only&amp;nbsp; Enter this keyword to accept ClientHellos only from a client&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using SSLV3&lt;BR /&gt;&amp;nbsp; tlsv1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLSv3&lt;BR /&gt;&amp;nbsp; tlsv1-only&amp;nbsp; Enter this keyword to accept ClientHellos only from a client&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using TLSV1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 19:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519098#M615459</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T19:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519099#M615460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA(config)# ssh version 2&lt;BR /&gt;ASA(config)# sh ssh&lt;BR /&gt;Timeout: 60 minutes&lt;BR /&gt;Version allowed: 2&lt;BR /&gt;0.0.0.0 0.0.0.0 outside&lt;BR /&gt;0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that changed to verizon 2 only but timeout stayed 60 minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh ssl&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;BR /&gt;ASA(config)# ssl server-version ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and either SSLv3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; or TLSv1 will be negotiated&lt;BR /&gt;&amp;nbsp; sslv3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLv3&lt;BR /&gt;&amp;nbsp; sslv3-only&amp;nbsp; Enter this keyword to accept ClientHellos only from a client&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using SSLV3&lt;BR /&gt;&amp;nbsp; tlsv1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLSv3&lt;BR /&gt;&amp;nbsp; tlsv1-only&amp;nbsp; Enter this keyword to accept ClientHellos only from a client&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using TLSV1&lt;BR /&gt;ASA(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should i do here.&amp;nbsp; According to the vendor ssl 2.0 should be off, but i can't check the status. Pls help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 20:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519099#M615460</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T20:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519100#M615461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To negotiate only SSlv3&lt;/P&gt;&lt;P&gt;ssl server-version sslv3-only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to change the timeout (whole different story) for SSH:&lt;/P&gt;&lt;P&gt;ssh timeout ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 20:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519100#M615461</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T20:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519101#M615462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;60 minutes is fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i do the following: ssl server-version sslv3-only ....will this give me any issue..for example we have OWA for exchange ...also for any reason if there is issue how should go back to my old settings...agian Federico thanks for this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 20:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519101#M615462</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T20:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519102#M615463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you might run into issues if you have any application running on any other SSL version.&lt;/P&gt;&lt;P&gt;By adding the command sslv3-only, the ASA will only support SSLv3.&lt;/P&gt;&lt;P&gt;Before doing this, make sure it will not affect any application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To do a rollback is not much of a problem...&lt;/P&gt;&lt;P&gt;Just copy/paste the output from:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run ssh&lt;/P&gt;&lt;P&gt;sh run ssl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Back to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 20:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519102#M615463</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T20:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519103#M615464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Without making any changes with our current configs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i do "sh run ssl" it comes out empty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh run ssl&lt;BR /&gt;ASA(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can be the reason of this.&amp;nbsp; How does vendor test our IP address and says that we are allowing ssl 2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only thing i am concern about is that we have VPN connection to remote location that also connect with asa5510 and Outlook we app(that check the certifcate and it says Version 3)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 20:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519103#M615464</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T20:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519104#M615465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also can be just take out ssl2 and keep others like sslv3 and tlsv1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and either SSLv3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; or TLSv1 will be negotiated&lt;BR /&gt;&amp;nbsp; sslv3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLv3&lt;BR /&gt;&amp;nbsp; sslv3-only&amp;nbsp; Enter this keyword to accept ClientHellos only from a client&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using SSLV3&lt;BR /&gt;&amp;nbsp; tlsv1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLSv3&lt;BR /&gt;&amp;nbsp; tlsv1-only&amp;nbsp; Enter this keyword to accept ClientHellos only from a client&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using TLSV1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 20:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519104#M615465</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T20:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519105#M615466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason &lt;BR /&gt;sh run ssl &lt;BR /&gt;does not show anything is because you have the default values. &lt;BR /&gt;To check what those settins are use &lt;BR /&gt;sh run all ssl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 21:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519105#M615466</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-07T21:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519106#M615467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks: i got the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh run all ssl&lt;BR /&gt;ssl server-version any&lt;BR /&gt;ssl client-version any&lt;BR /&gt;ssl encryption afsd-sha1 .........(long key)&lt;BR /&gt;ASA(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i change to this : &lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;ssl server-version sslv3-only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will something go wrong with ssl encryption..or anything ..and if i need to go back to any ..should i use following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl server-version any (let me know if this is wrong)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again for your time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 21:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519106#M615467</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2010-12-07T21:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ssl and ssh</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519107#M615468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s8.html#wp1511377"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s8.html#wp1511377&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1511389table1511387" style="width: 80%;"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;&lt;EM class="cCi_CmdItalic"&gt;sslv3-only&lt;/EM&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1511405"&gt;&lt;/A&gt;&lt;P class="pB1_Body1"&gt;The security appliance accepts only SSL version 3 client hellos, and uses only SSL version 3.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer the above link and it has the command syntax.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl server-version any is correct syntax.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 03:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-ssl-and-ssh/m-p/1519107#M615468</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-08T03:00:37Z</dc:date>
    </item>
  </channel>
</rss>

