The IPA server uses TLSv1.0 and includes medium encryption ciphers
Issue
-
Our sercurity checked the ldaps / https connection on our (almost default-out-of-the-box) IPA server.
-
For HTTPS:
- Turn off TLSv1.0 (against BEAST);
- Turn off Medium grade encryption;
- Turn off 3DES and RC4;
- PFS is not offered while this cipher-wise would be possible;
- Secure Client-Initiated Renegotiation does not work.
-
For LDAPs:
- Turn off TLSv1.0 (against BEAST);
- Turn off Medium grade encryption;
- Secure Client-Initiated Renegotiation does not work.
-
Environment
- Red Hat Enterprise Linux (RHEL) 7.2
- ipa-server-4.2.0
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.