EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Preview
Running a vulnerability scan we found the server can fall back into non-secure protocols. It is Data Center Expert ver. 7.4.2
Question
How to disable SSL v2, SSL v3, TLS 1.0 and TLS 1.1? While leaving TLS 1.2 onwards as the only option available.
Also. Non-secure connections should not be permitted.
I found a similar thread but can't find an specific answer: DCO - Vulnerability using Protocol SSL - TLS
(CID:113642463)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Hi Roberto,
There is no place in the UI where you can configure this at this time. Additionally, some older APC devices / firmwares may require the older versions of TLS and disabling that would cause communications to cease with those older devices. I will be sure to let engineering know of your concern and perhaps an enhancement request could make it to DCE but I can not promise.
Steve.
(CID:113642761)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Hi Roberto,
There is no place in the UI where you can configure this at this time. Additionally, some older APC devices / firmwares may require the older versions of TLS and disabling that would cause communications to cease with those older devices. I will be sure to let engineering know of your concern and perhaps an enhancement request could make it to DCE but I can not promise.
Steve.
(CID:113642761)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Understood, thanks Steven M.
(CID:113642926)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
I am currently at Data Center Expert 7.2.2 , what version do I need to upgrade to in order to enable TLS 1.2 ? -Thanks
(CID:114231680)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Hi,
I upgraded to 7.6.0 and run another scan. we are still failing because of TLSv1. when trying to disable it under System-> Server access I get "the currently displayed page contains invalid values" error message.
does anyone know how I could disable TLSv1?
(CID:134686493)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Bump
(CID:137109011)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Hello All,
Starting with Data Center Expert version 7.5.0 you can now disable select version of SSL/TLS. Below is the section from the release notes for v7.5.0:
SSL protocol selection
You can now select the allowed SSL protocols for the web server and private proxy in the System> Administration Settings > Server Access option. You can select multiple TLS and SSL protocol versions for the web server. You can select only one protocol for the private proxy.
Kind Regards,
Cory
FYI: Roberto Pereira, shirin, John Smith, & stephen bryant
(CID:137109746)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2024-04-08 01:34 AM
Thanks!
(CID:137728394)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: β2020-07-03 01:35 PM . Last Modified: β2023-10-22 01:16 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.