<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R77.30 w/gaia using TLSv1 for LDAPS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97033#M10419</link>
    <description>&lt;P&gt;Hello.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The short:&lt;/P&gt;&lt;P&gt;I need LDAPS to use tlsv1.2 instead of tlsv1 in my R77.30 gateway clsuter.&amp;nbsp; Has anyone else had to manually change this?&lt;/P&gt;&lt;P&gt;The long:&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have an R77.30 JHF 351 two node cluster that has LDAPS configured for Identity Awareness.&amp;nbsp; &amp;nbsp;I have all the thumbprints, and have the encryption min and max set to "Strong."&amp;nbsp; &amp;nbsp;In global properties, we have min/max version of TLSv1.2.&amp;nbsp; We have gone into GuiDBedit and change the "other" ssl min and max to tlsv1.2.&lt;/P&gt;&lt;P&gt;All this, and when the firewall makes an LDAP request of our active directory DC's, it uses TLSv1.&amp;nbsp; &amp;nbsp;I have packet captures from the gateways showing that they are using tlsv1, and the AD logs basically say that the client has no compatible ciphers.&lt;/P&gt;&lt;P&gt;I have a TAC case open, but after several hours in a remote session yesterday, we were unable to figure out how to made LDAPS use TLSv1.2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even stranger, I have another R77.30 jhf 345 solution, two clusters of two 23500's each running VSX.&amp;nbsp; All the VS's that are configured to use the same DC's for IA work fine.&amp;nbsp; &amp;nbsp;The VSX management, however, also tries TLSv1 and fails. All other services are using TLSv1.2 successfully.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TAC is currently comparing the cpinfo output from both solutions to see if they can find why the VS's are working and why VSX and straight up Gaia are not.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 17:47:17 GMT</pubDate>
    <dc:creator>Steve_Marouchoc</dc:creator>
    <dc:date>2020-09-18T17:47:17Z</dc:date>
    <item>
      <title>R77.30 w/gaia using TLSv1 for LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97033#M10419</link>
      <description>&lt;P&gt;Hello.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The short:&lt;/P&gt;&lt;P&gt;I need LDAPS to use tlsv1.2 instead of tlsv1 in my R77.30 gateway clsuter.&amp;nbsp; Has anyone else had to manually change this?&lt;/P&gt;&lt;P&gt;The long:&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have an R77.30 JHF 351 two node cluster that has LDAPS configured for Identity Awareness.&amp;nbsp; &amp;nbsp;I have all the thumbprints, and have the encryption min and max set to "Strong."&amp;nbsp; &amp;nbsp;In global properties, we have min/max version of TLSv1.2.&amp;nbsp; We have gone into GuiDBedit and change the "other" ssl min and max to tlsv1.2.&lt;/P&gt;&lt;P&gt;All this, and when the firewall makes an LDAP request of our active directory DC's, it uses TLSv1.&amp;nbsp; &amp;nbsp;I have packet captures from the gateways showing that they are using tlsv1, and the AD logs basically say that the client has no compatible ciphers.&lt;/P&gt;&lt;P&gt;I have a TAC case open, but after several hours in a remote session yesterday, we were unable to figure out how to made LDAPS use TLSv1.2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even stranger, I have another R77.30 jhf 345 solution, two clusters of two 23500's each running VSX.&amp;nbsp; All the VS's that are configured to use the same DC's for IA work fine.&amp;nbsp; &amp;nbsp;The VSX management, however, also tries TLSv1 and fails. All other services are using TLSv1.2 successfully.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TAC is currently comparing the cpinfo output from both solutions to see if they can find why the VS's are working and why VSX and straight up Gaia are not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 17:47:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97033#M10419</guid>
      <dc:creator>Steve_Marouchoc</dc:creator>
      <dc:date>2020-09-18T17:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 w/gaia using TLSv1 for LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97123#M10420</link>
      <description>&lt;P&gt;Maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;knows but I don’t think there is anything specific requires to tell IDA to use TLS 1.2.&lt;BR /&gt;You might also compare hotfixes between the two systems.&lt;/P&gt;
&lt;P&gt;That said R77.30 has been End of Support for a year now and you should really look at upgrading.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 00:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97123#M10420</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-21T00:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 w/gaia using TLSv1 for LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97151#M10421</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It's in a layer "below" IDA &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1635"&gt;@Liel_Shaish&lt;/a&gt;&amp;nbsp;, do you know?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:10:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97151#M10421</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-09-21T08:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 w/gaia using TLSv1 for LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97186#M10422</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; I am aware of the eos, but scheduling a window where all out backup products may be at risk for the transition has been more than a little difficult. And yes, TOC is comparing the cpinfo from both boxes to see if we can find why&amp;nbsp; the difference.&amp;nbsp; But I thought I'd ask the community to see if anyone else has had experience.&amp;nbsp; Thanks again!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 12:05:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97186#M10422</guid>
      <dc:creator>Steve_Marouchoc</dc:creator>
      <dc:date>2020-09-21T12:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 w/gaia using TLSv1 for LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97211#M10423</link>
      <description>&lt;P&gt;This may not be super helpful and maybe tac has already done this with you, but if it was me I would find the process that is making the tls call and figure out how to put it in debug mode. There should be something indicating what its doing any why. I always forget if its pep or pdp but my guess is its one of those making the tls call.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 18:29:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97211#M10423</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-09-21T18:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 w/gaia using TLSv1 for LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97216#M10424</link>
      <description>&lt;P&gt;pdp is responsible for doing the LDAP lookups.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 19:28:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-w-gaia-using-TLSv1-for-LDAPS/m-p/97216#M10424</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-21T19:28:59Z</dc:date>
    </item>
  </channel>
</rss>

