<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Verifying TLS 1.2 Cipher suites disabled? in Security</title>
    <link>https://community.splunk.com/t5/Security/Verifying-TLS-1-2-Cipher-suites-disabled/m-p/600924#M16146</link>
    <description>&lt;P&gt;I do see this document describes configuration of using TLS 1.2 cipher suites that are marked secure by PCI requirements.&lt;BR /&gt;Just looking to understand the ramifications of connectivity if i do change the web.conf and server.conf with the values listed in this link&lt;BR /&gt;Would we also have to update our certificates if we use the specific ciphers?&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/Ciphersuites" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/Ciphersuites&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2022 18:06:18 GMT</pubDate>
    <dc:creator>sonicZ</dc:creator>
    <dc:date>2022-06-07T18:06:18Z</dc:date>
    <item>
      <title>Verifying TLS 1.2 Cipher suites disabled?</title>
      <link>https://community.splunk.com/t5/Security/Verifying-TLS-1-2-Cipher-suites-disabled/m-p/600572#M16141</link>
      <description>&lt;P&gt;We have a PCI requirement to disable TLS1.1 or TLS1.0 cipher suites such as&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;- TLSv1.0 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
&lt;DIV class=""&gt;- TLSv1.0 TLS_DHE_RSA_WITH_AES_256_CBC_SHA&lt;BR /&gt;- TLSv1.0 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA&lt;BR /&gt;- TLSv1.0 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA&lt;BR /&gt;- TLSv1.1 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
&lt;DIV class=""&gt;- TLSv1.1 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
&lt;DIV class=""&gt;- TLSv1.1 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
&lt;DIV class=""&gt;Among others...
&lt;DIV class=""&gt;&amp;nbsp;
&lt;DIV class=""&gt;I checked a few docs and tested disabling anything less then TLS 1.2 in
&lt;DIV class=""&gt;
&lt;PRE&gt;sslVersions =  tls1.2&lt;/PRE&gt;
&lt;DIV class=""&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/SetyourSSLversion" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/SetyourSSLversion&lt;/A&gt;
&lt;DIV class=""&gt;&amp;nbsp;
&lt;DIV class=""&gt;How can i be sure the above cipher suites are disabled and TLS 1.2 is the only allowed?
&lt;DIV class=""&gt;from previous posts i read we can use openssl to test via and look for any errors or the full certificate response if its open?&lt;BR /&gt;openssl s_client -connect ipaddress:port -tls1_1our currrent server.conf is as follows&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;BR /&gt;Here is our current server.conf&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;PRE&gt;[sslConfig]&lt;BR /&gt;sslVersions = *,-ssl2&lt;BR /&gt;sslVersionsForClient = *,-ssl2&lt;BR /&gt;cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 07 Jun 2022 18:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-TLS-1-2-Cipher-suites-disabled/m-p/600572#M16141</guid>
      <dc:creator>sonicZ</dc:creator>
      <dc:date>2022-06-07T18:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Verifying TLS 1.2 Cipher suites disabled?</title>
      <link>https://community.splunk.com/t5/Security/Verifying-TLS-1-2-Cipher-suites-disabled/m-p/600924#M16146</link>
      <description>&lt;P&gt;I do see this document describes configuration of using TLS 1.2 cipher suites that are marked secure by PCI requirements.&lt;BR /&gt;Just looking to understand the ramifications of connectivity if i do change the web.conf and server.conf with the values listed in this link&lt;BR /&gt;Would we also have to update our certificates if we use the specific ciphers?&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/Ciphersuites" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/Ciphersuites&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 18:06:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-TLS-1-2-Cipher-suites-disabled/m-p/600924#M16146</guid>
      <dc:creator>sonicZ</dc:creator>
      <dc:date>2022-06-07T18:06:18Z</dc:date>
    </item>
  </channel>
</rss>

