07-30-2021 12:25 PM - edited 07-31-2021 04:47 PM
Hello team,
After scanning vulnerabilities at the Cisco DNA Center, it was found that:
- Replace the 'Diffie-Hellman' with a safer group;
"The remote server is affected by a cryptographical weakness.
Disable weak cipher suites in the server's configuration.
It is recommended to use ECDH cipher suites instead and generate a strong, unique Diffie Hellman Group (2048-bit or stronger)".
- Increase the private key to 2048 bits or more.
"The remote server is affected by a cryptographical weakness.
Configure your SSH server so it uses moduli longer than 1024 bits and make sure that the diffie-hellman-group1-sha1 algorithm is disabled."
I couldn't find documentation with steps on how to perform these procedures.
Some direction?
All the best
Solved! Go to Solution.
07-30-2021 02:39 PM
After scanning vulnerabilities at the Cisco DNA Center, it was found that:
We are not sure what scanning you did for what ports ? you need to provide complete output.
as per the suggestion if you looking HTTPS Look at the below guide : (this is based on assumption that you have vulnerable https)
07-30-2021 01:02 PM
@fongaratto : Check you check this document " Certificate and Private key"
07-30-2021 01:50 PM
Hello,
I saw this and many other links, unfortunately, I did not find the procedure I need in them.
Still, I appreciate your help.
Best regards.
07-30-2021 02:39 PM
After scanning vulnerabilities at the Cisco DNA Center, it was found that:
We are not sure what scanning you did for what ports ? you need to provide complete output.
as per the suggestion if you looking HTTPS Look at the below guide : (this is based on assumption that you have vulnerable https)
07-31-2021 04:44 PM
Hello,
Below includes what I need help doing:
Findings 1:
"The remote server is affected by a cryptographical weakness.
Configure your SSH server so it uses moduli longer than 1024 bits and make sure that the diffie-hellman-group1-sha1 algorithm is disabled."
Findings 2:
"The remote server is affected by a cryptographical weakness.
Disable weak cipher suites in server's configuration.
It is recommended to use ECDH cipher suites instead and generate a strong, unique Diffie Hellman Group (2048-bit or stronger)".
I appreciate the help and attention.
08-01-2021 01:48 AM
The above document should be able to help you to get new one.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide