Bug 44833 - make univention-management-console-server ciphers configurable
Summary: make univention-management-console-server ciphers configurable
Status: CLOSED DUPLICATE of bug 40998
Alias: None
Product: UCS
Classification: Unclassified
Component: UMC (Generic)
Version: UCS 4.2
Hardware: Other Linux
: P5 normal
Target Milestone: ---
Assignee: UMC maintainers
QA Contact: UMC maintainers
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-21 10:16 CEST by Jens Thorp-Hansen
Modified: 2023-06-19 15:28 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?: Yes
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2017061521000462
Bug group (optional):
Customer ID: 07142
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jens Thorp-Hansen univentionstaff 2017-06-21 10:16:12 CEST
Relevance: important for PCI-DSS

Pentest:
Port 6670 weak ciphers:
 
Accepted TLSv1.2 112 bits DES-CBC3-SHA
Accepted TLSv1.2 56 bits DES-CBC-SHA
Accepted TLSv1.1 112 bits DES-CBC3-SHA
Accepted TLSv1.1 56 bits DES-CBC-SHA
Accepted TLSv1.0 112 bits DES-CBC3-SHA
Accepted TLSv1.0 56 bits DES-CBC-SHA
Accepted TLSv1.0 128 bits  RC4-SHA                      
Accepted TLSv1.0 128 bits  RC4-MD5  
Accepted TLSv1.1 128 bits  RC4-SHA                      
Accepted TLSv1.1 128 bits  RC4-MD5
Accepted TLSv1.2 128 bits  RC4-SHA                      
Accepted TLSv1.2 128 bits  RC4-MD5

The used ciphers should be configurable.
Comment 1 Florian Best univentionstaff 2017-06-21 12:03:01 CEST
I fixed this yesterday in Bug #40998.

*** This bug has been marked as a duplicate of bug 40998 ***