• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to disable Weak Cipher

Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
10 Posts 3 Posters 4.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    phospher
    last edited by Apr 18, 2011, 7:11 PM

    How can I disable the cipher "DES-CBC-SHA"? It is a 56 bit DES Key. I've verified this with openssl and it is considered "weak".

    Thanks,

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Apr 19, 2011, 5:02 PM

      Disable from where? OpenVPN? IPsec?

      Both of those places use the cipher(s) you explicitly choose, it wouldn't be automatically selected.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • P
        phospher
        last edited by Apr 19, 2011, 6:38 PM

        The ssl login to the webconfigurator. A change to lighttpd should do the trick.

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Apr 19, 2011, 7:12 PM

          What are you trying that shows that cipher is even being used?

          When I connect, the browser reports it is using Camellia-256.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • P
            phospher
            last edited by Apr 19, 2011, 7:28 PM

            openssl. from freebsd command line:

            openssl s_client -connect "x.x.x.x:443 -cipher LOW 
            

            You have to "force" the LOW cipher.

            1 Reply Last reply Reply Quote 0
            • J
              jimp Rebel Alliance Developer Netgate
              last edited by Apr 19, 2011, 7:38 PM

              So if you have to force it I'm not sure I see the problem. :-)

              I presume you're talking about this lighttpd modification?

              http://linuxadminzone.com/disable-weak-ssl-ciphers-in-lighttpd-in-linux/

              It might be worth opening a feature request ticket in redmine to make that change if it's really needed.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • P
                phospher
                last edited by Apr 19, 2011, 8:23 PM

                So if you have to force it I'm not sure I see the problem. :-)

                The issue is that if someone has their browser set to use the low cipher it could be intercepted and cracked because of the weak cipher strength. I haven't read that specific article but yes, that is exactly what I'm talking about.  I'm sure you've come across the SSLv2 issues and the fact that they are weak ciphers and should not be used. Same for this specific cipher, it should not be enabled.

                There are also a few other minor issues that only an enterprise would likely care about..  Like the fact the HttpOnly cookie is not set, the secure attribute for cookies is not set, and autocomplete is enabled. Again, minor but someone at some point may care (client?).

                1 Reply Last reply Reply Quote 0
                • J
                  jimp Rebel Alliance Developer Netgate
                  last edited by Apr 19, 2011, 8:41 PM

                  We had autocomplete disabled for the longest time but convenience and user pressure led us to re-enable it. It could be made an option, though.

                  Not sure about the cookie settings, someone else may have to comment on those.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • S
                    sullrich
                    last edited by Apr 19, 2011, 9:06 PM

                    These changes have been committed.

                    1 Reply Last reply Reply Quote 0
                    • P
                      phospher
                      last edited by Apr 19, 2011, 10:41 PM

                      That's great. Thanks guys!

                      1 Reply Last reply Reply Quote 0
                      10 out of 10
                      • First post
                        10/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received