cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5113
Views
5
Helpful
2
Replies

How to disable ssl-static-key-ciphers on Cisco ASA?

FMS101
Level 1
Level 1

I'm running version 9.12(4)7 on ASA 5525.  A scan of the firewall flagged  the following  vulnerability.

 

TLS/SSL Server Supports The Use of Static Key Ciphers

 

Any idea how this can be disabled?

 

Thanks.

1 Accepted Solution

Accepted Solutions
2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Have you tried disabling all non-DHE ciphers?

See the posting by @Karsten Iwen here:

https://community.cisco.com/t5/vpn/anyconnect-perfect-forward-secrecy/td-p/3324415

FMS101
Level 1
Level 1

That worked.

 

Thank you.

Review Cisco Networking for a $25 gift card