NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

bbaraniec's avatar
bbaraniec
Luminary
Mar 31, 2015

Apache and openssl version RAIDiator 4.2.27.

Hi,

Could anyone please tell me what are the versions of apache and openssl in RAIDiator 4.2.27.?
Thank you in advance.

13 Replies

Replies have been turned off for this discussion
  • I am using a PKI certificate and if I remember correctly by the time of csr there was no option for SHA2.
    At the moment my connection is encrypted using EAS_256_CBC with SHA1 and DHE_RSA as key exchange that's TLSv1. I have turned off all SSLs.
    I want to fix that week spot:
    TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) 128
    TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 128
    TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) 112
    TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (0x16) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 112
    TLS_RSA_WITH_AES_256_CBC_SHA (0x35) 256
    TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x39) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 256

    The perfect choice would be
    SSLCipherSuite AES256+EECDH:AES256+EDH:!aNULL + TLSv1.2 but EECDH is not supported and I haven't tested AES256+EDH yet.
  • StephenB's avatar
    StephenB
    Guru - Experienced User
    You'd need to work with your cert authority on sha-256 hashing.

    I believe your three weak spots on encryption are because of DH 1024 bits. Updating apache might be needed to shore that up.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More