04-12-2012 02:51 PM - edited 03-10-2019 05:39 AM
I am trying to communicate with a Cisco IPS 4240 device using SSL while having the FIPS security setting enabled on the client. This is not possible because the device does not support the TLS extensions in the Client Hello packet (RFC 5746) being sent by the client when using TLS (SSL3 and lower are not FIPS compliant). The IDM application that communicates with the device does not send these TLS extensions (im seeing this with WireShark) so it is able to connect to it.
Is there any way to make the 4240 support these TLS extensions ?
Solved! Go to Solution.
04-16-2012 08:21 AM
This is related to the bugs below. The initial workaround will be included in the 7.1.5 release which is set to support the 4240 platform among others. This will allow the IPS webserver to ignore the extensions in the short-term. The long-term fix will require an update to the webserver to ensure that it is fully RFC 5746 compliant.
Todd
04-16-2012 08:21 AM
This is related to the bugs below. The initial workaround will be included in the 7.1.5 release which is set to support the 4240 platform among others. This will allow the IPS webserver to ignore the extensions in the short-term. The long-term fix will require an update to the webserver to ensure that it is fully RFC 5746 compliant.
Todd
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide