12-12-2017 01:40 AM - edited 02-21-2020 10:41 AM
Hi
I want to be able to enable or disable specific ciphers or TLS versions for a specific authentication protocol definition
Policy -> Policy elements -> Authentication -> Allowed protocols
Currently all I can do is enable or disable weak ciphers (see attached picture), or enable or disable TLS1.0/TLS1.1 installation-wide (Admin -> System -> Settings -> Protocols -> Security settings).
Are there any plans for doing this in the future ?
If not, then please add options to enable or disable these already-existing settings to the auth protocol definition settings.
For cipher suite selections, I don't need a fancy cipher suite selection UI - a simple string field for cipher suites (as input to OpenSSL) would be fine. But a simple "enable weak ciphers" is not good enough, if I for some reason need to disable a specific cipher set.
Regards Henrik
12-16-2017 12:11 AM
Hello Henrik,
My name is Tal Surasky and I'm one of ISE's product manager.
Currently changing protocols settings is something we can do in a deployment-wide settings only and not as you requested, per policy.
Can you please elaborate on the use case and why do you need this option?
Thanks
Tal
01-02-2018 06:06 AM
The use cases for changing TLS cipher/protocol settings per policy, and not deployment-wide, are the following:
Eg. Use EAP-PEAP-MD5 or similar as replacement for MAB, for devices that support EAP – but will most certainly have devices that only support older protocol versions and weaker ciphers
04-18-2019 03:32 AM
Hi henrikj
Did you get a response on this? l need to do the same too.
Thanks
Vusa
05-01-2019 03:34 AM
No :-(
05-11-2019 05:11 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide