08-06-2010 01:07 PM
Some SSL issues discovered (for example by Nessus 4 here):
1.The certificate (of course not the default), does not contain a FQDN required for checking. The hostname is caonfigureble - but a domain can't be configured on the RV012. Remediation would be a much better certificate handling, plus the ability to configure a domain in addition ot a hostname.this must be combined to the CN in the self-signed certificate instead of hte first MAC address.
2. Weak ciphers offered by the Web server must be removed.
3. Medium cipher should be removed from the Web server.
SSL Certificate with Wrong Hostname |
|
SSL Anonymous Cipher Suites Supported |
|
SSL Medium Strength Cipher Suites Supported |
|
08-06-2010 01:40 PM
I believe some of these are why the current v2 RV0xx's devices fail credit card PCI validations with companies like Security Metrics. My ASA's out there do not fail PCI validations, who can Cisco allow their SMB routers to?
08-06-2010 02:27 PM
Add the absent support for real certificates from trusted authorities.
Between the lines... done several IT security audits over the years in organisations issuing and clearing major US credit card here in Europe, all previously reviewd by trusted parties of the licensing organisations. Can't further comment here - except that I can safely say, their expectations are not extraordinary high.
08-06-2010 03:08 PM
Try it on a RV082 with v2.0.0.19 with SSL enabled (with or without remote management enabled) and see what you get. First Data, one of the largest CC clearing houses in the US, uses Security Metrics and it will fail if SSL is enabled no matter what becuase of the type of SSL they allow.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide