NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
bbaraniec
Mar 31, 2015Luminary
Apache and openssl version RAIDiator 4.2.27.
Hi,
Could anyone please tell me what are the versions of apache and openssl in RAIDiator 4.2.27.?
Thank you in advance.
Could anyone please tell me what are the versions of apache and openssl in RAIDiator 4.2.27.?
Thank you in advance.
13 Replies
Replies have been turned off for this discussion
- bbaraniecLuminaryI am using a PKI certificate and if I remember correctly by the time of csr there was no option for SHA2.
At the moment my connection is encrypted using EAS_256_CBC with SHA1 and DHE_RSA as key exchange that's TLSv1. I have turned off all SSLs.
I want to fix that week spot:TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) 128
TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 128
TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) 112
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (0x16) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 112
TLS_RSA_WITH_AES_256_CBC_SHA (0x35) 256
TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x39) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 256
The perfect choice would be
SSLCipherSuite AES256+EECDH:AES256+EDH:!aNULL + TLSv1.2 but EECDH is not supported and I haven't tested AES256+EDH yet. - StephenBGuru - Experienced UserYou'd need to work with your cert authority on sha-256 hashing.
I believe your three weak spots on encryption are because of DH 1024 bits. Updating apache might be needed to shore that up.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!