Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Upgrading WebGui TLS 1.0 to TLS 1.2 for PCI/DSS requirement

    Scheduled Pinned Locked Moved webGUI
    4 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marskarthik
      last edited by

      Hi,

      We are using PFSense in a PCI/DSS environment and during recent audit we have been instructed to upgrade the WebGui TLS v1.0 to TLS V1.2. I couldn't find any guide to upgrade the webgui. Since this is mandatory requirement for PCI/DSS we need to do it ASAP.

      Let me know how to upgrade the TLS.

      We use 2.0.2-RELEASE
      FreeBSD 8.1-RELEASE-p13

      Karthik

      pfsense.png
      pfsense.png_thumb

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        @marskarthik:

        We use 2.0.2-RELEASE

        Is this some bad joke?!?! https://doc.pfsense.org/index.php/Versions_of_pfSense_and_FreeBSD

        @marskarthik:

        during recent audit we have been instructed to upgrade the WebGui TLS v1.0 to TLS V1.2.

        Sounds like an excellent opportunity to sack those absolutely useless "auditors" as well.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          So your auditors didn't like that you were using tls 1, but didn't give 2 shits that your actual firewall software is from 2012 and no longer supported.  Needless to say freebsd version as well….

          Im with dok - is this some sort of joke?

          Here is my suggestion for your remediation of that audit finding - update to current version ;)  And then you will have your tls 1.2 support..

          pfsense12tls.png
          pfsense12tls.png_thumb

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • C
            chrcoluk
            last edited by

            I did sort of almost spit out my drink when I noticed you using a code base thats no longer supported.

            I can confirm on 2.4 TLS 1.2 is used.

            So update the pfsense to a newer code base and your problem is solved.

            pfSense CE 2.7.2

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.