cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

479
Views
5
Helpful
2
Replies

Cisco ISE 2.6 "set ECDHE and/or DHE cipher suites as preferred" .

Hi,

 

Its possible, set ECDHE cipher suites as preferred, in SSL server?

 

If yes, how?

 

ISE 2.6

 

Thanks!

 

1 ACCEPTED SOLUTION

Accepted Solutions
Greg Gibbs
Cisco Employee

There is no direct method to set the preferred cipher as there is no direct access to the underlying OS. There are some mechanisms to remove support for some insecure ciphers, so you might look at these options.

  1. Enable FIPS Mode
  2. Remove support for specific ciphers in Administration > System > Settings > Security Settings

View solution in original post

2 REPLIES 2
inderdeeps
Enthusiast
Greg Gibbs
Cisco Employee

There is no direct method to set the preferred cipher as there is no direct access to the underlying OS. There are some mechanisms to remove support for some insecure ciphers, so you might look at these options.

  1. Enable FIPS Mode
  2. Remove support for specific ciphers in Administration > System > Settings > Security Settings

View solution in original post

Create
Recognize Your Peers
Content for Community-Ad

ISE Webinars



Did you miss a previous ISE webinar?

CiscoISE YouTube Channel