07-18-2022 07:33 AM
Hi we got the below info from vulnerability security scan from cisco switch. I am not sure how to allow strong key exchange. Anyone can share some experience? Thank you
Change the SSL/TLS server configuration to only allow strong key exchanges. Key exchanges should provide at least 112 bits of security, which translates to a minimum key size of 2048 bits for Diffie Hellman and RSA key exchanges.
Weak SSL/TLS Key Exchange
Solved! Go to Solution.
07-18-2022 07:45 AM - edited 07-18-2022 07:48 AM
@Leftz do you even use SSL/TLS on the switches? as most organisations I work with do not. I therefore just disable SSL/TLS, use the command "no ip http secure-server".
You can expictly configure the ciphersuite "ip http secure-ciphersuite <ciphersuite>"
You can also limit SSL/TLS connections using an ACL
07-18-2022 07:45 AM - edited 07-18-2022 07:48 AM
@Leftz do you even use SSL/TLS on the switches? as most organisations I work with do not. I therefore just disable SSL/TLS, use the command "no ip http secure-server".
You can expictly configure the ciphersuite "ip http secure-ciphersuite <ciphersuite>"
You can also limit SSL/TLS connections using an ACL
07-18-2022 08:32 AM
Thank you Rob. I think you are correct.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide