Disable TLS v1 and TLS v1.1 in tog-pegasus
Issue
- Scanners in a 3rd party product report port 5989 as using TLSv1 and TLSv1.1:
5989/tcp
Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346) include cipher suites based on the DES (Data Encryption Standard) and IDEA (International Data Encryption Algorithm) algorithms.
DES and IDEA algorithms are no longer recommended for general use in TLS, and have been removed from TLS version 1.2.
Negotiated with the following insecure cipher suites: TLS 1.0 ciphers:
TLS_RSA_WITH_IDEA_CBC_SHA
TLS 1.1 ciphers:
TLS_RSA_WITH_IDEA_CBC_SHA
Environment
- Red hat Enterprise Linux 6.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.