cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1952
Views
5
Helpful
2
Replies

Cisco ISE 2.6 "set ECDHE and/or DHE cipher suites as preferred" .

Hi,

 

Its possible, set ECDHE cipher suites as preferred, in SSL server?

 

If yes, how?

 

ISE 2.6

 

Thanks!

 

1 Accepted Solution

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

There is no direct method to set the preferred cipher as there is no direct access to the underlying OS. There are some mechanisms to remove support for some insecure ciphers, so you might look at these options.

  1. Enable FIPS Mode
  2. Remove support for specific ciphers in Administration > System > Settings > Security Settings

View solution in original post

2 Replies 2

Greg Gibbs
Cisco Employee
Cisco Employee

There is no direct method to set the preferred cipher as there is no direct access to the underlying OS. There are some mechanisms to remove support for some insecure ciphers, so you might look at these options.

  1. Enable FIPS Mode
  2. Remove support for specific ciphers in Administration > System > Settings > Security Settings
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: