<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.10 cipher_util issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187495#M34569</link>
    <description>&lt;P&gt;Could not agree more&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23046"&gt;@Fire_Verse&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jul 2023 12:34:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-07-25T12:34:04Z</dc:date>
    <item>
      <title>R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142771#M22127</link>
      <description>&lt;P&gt;&lt;STRONG&gt;cipher_util&lt;/STRONG&gt; does no longer work for multiportal in R81.10, look for yourself:&lt;/P&gt;
&lt;P&gt;- start cipher_util&lt;/P&gt;
&lt;P&gt;- display multiportal cipher list&lt;/P&gt;
&lt;P&gt;- disable one cipher&lt;/P&gt;
&lt;P&gt;- display cipher list shows the cipher as disabled&lt;/P&gt;
&lt;P&gt;- quit cipher_util and type y save:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Would you like to save configuration? [y/N] y&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Successfuly reconfigured&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Exiting cipher tool...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- start cipher_util&lt;/P&gt;
&lt;P&gt;- display multiportal cipher list&lt;/P&gt;
&lt;P&gt;---&amp;gt; you will see that nothing was changed and cipher_util has not saved the changes !&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 12:41:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142771#M22127</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-03T12:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142816#M22135</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for raising this issue&lt;/P&gt;
&lt;P&gt;We are aware of this issue and working on a fix, will be released in R81.20 once&amp;nbsp;the tests are completed successfully&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;cipher_util tool works as expected for HTTPS Inspection&lt;/LI&gt;
&lt;LI&gt;A valid Workaround of changing ciphers for Multi-portal is to install policy by running "&lt;SPAN&gt;fw fetch local" on the Gateway&lt;/SPAN&gt;&amp;nbsp;right after "save configuration" step&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Matan&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 13:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142816#M22135</guid>
      <dc:creator>matangi</dc:creator>
      <dc:date>2022-03-03T13:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142825#M22136</link>
      <description>&lt;P&gt;Replicated issue and workaround on R81.10 and R80.40 GWs. Is there an SK for this issue already ?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 17:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142825#M22136</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-02T17:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142898#M22146</link>
      <description>&lt;P&gt;Is it correct that this issue also is present in R81 &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32928"&gt;@matangi&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 12:40:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142898#M22146</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-03T12:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142902#M22148</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Yes, issue is present in R80.40 and higher releases&lt;/P&gt;
&lt;P&gt;We created a new SK for that matter, see&amp;nbsp;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178165" target="_blank"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178165&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Matan&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 13:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142902#M22148</guid>
      <dc:creator>matangi</dc:creator>
      <dc:date>2022-03-03T13:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142906#M22150</link>
      <description>&lt;P&gt;Indeed...tested on R80.40 and above, same issue. On R80.30, works fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 14:30:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142906#M22150</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-03T14:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142907#M22151</link>
      <description>&lt;P&gt;Good job! Just tested with that sk and worked like a charm.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 14:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/142907#M22151</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-03T14:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/162393#M28868</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32928"&gt;@matangi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Got the same problem in our upgrade from R80.30 to R81.10.&lt;/P&gt;&lt;P&gt;We tried the workaround in&amp;nbsp;&lt;SPAN&gt;sk178165,&lt;/SPAN&gt;&amp;nbsp;does not seem to work.&lt;/P&gt;&lt;P&gt;The only difference from the workaround is that after "Multi Portal" a got to select "TLS 1.2 Ciphers"&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 18:29:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/162393#M28868</guid>
      <dc:creator>chuck</dc:creator>
      <dc:date>2022-11-17T18:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/162565#M28919</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/46570"&gt;@chuck&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;In case the problem persists, Please open a service request to Check Point Support&lt;/P&gt;</description>
      <pubDate>Sun, 20 Nov 2022 09:29:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/162565#M28919</guid>
      <dc:creator>matangi</dc:creator>
      <dc:date>2022-11-20T09:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187442#M34555</link>
      <description>&lt;P&gt;So this has been a known issue for over a year? Hey Check Point how about:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Update sk126613 directly with&amp;nbsp;sk178165&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Create a hotfix for affected versions&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;How much more time do you need on this? Amazing.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 07:42:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187442#M34555</guid>
      <dc:creator>Fire_Verse</dc:creator>
      <dc:date>2023-07-25T07:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187457#M34556</link>
      <description>&lt;P&gt;- sk178165 is listed first under Known Limitations of sk126613&lt;/P&gt;
&lt;P&gt;- R81.20 includes a fix&lt;/P&gt;
&lt;P&gt;- there is a workaround for R80.40 -&amp;gt; R81.10&lt;/P&gt;
&lt;P&gt;As disabling ciphers for MultiPortal is no activity repeated every other day it is not so hard to live with it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 09:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187457#M34556</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-25T09:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187461#M34557</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"sk178165 is listed first under Known Limitations of sk126613" &amp;lt;-- This should be included within the steps, not added as an afterthought at the end of the SK.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;R81.20 includes a fix" &amp;lt;--Customer is not on R81.20, so this doesn't apply.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;there is a workaround for R80.40 -&amp;gt; R81.10" &amp;lt;-- That's not a "workaround" that is a missing step in the documentation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;As disabling ciphers for MultiPortal is no activity repeated every other day it is not so hard to live with it" &amp;lt;-- Maybe for you, but I have a customer with an outage because of this SK. This SK article has not been updated after 16 months and multiple reports of problems, sk178165 and&amp;nbsp;sk126613 have not been combined, this not to have been addressed in a hotfix, and the multiportal still has these ciphers enabled by default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If gateways are going to continue to be shipped this way, then the documentation should be spot on so that they can be quickly corrected and run as actual security devices.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Otherwise this cipher issue is going to be highlighted on any kind of vulnerability scan or pen test, and make it quite a challenge to demonstrate compliance to any reputable standard.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 22:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187461#M34557</guid>
      <dc:creator>Fire_Verse</dc:creator>
      <dc:date>2023-07-25T22:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187463#M34558</link>
      <description>&lt;P&gt;Yes, this world could be a better place 8)&lt;/img&gt; ! Missing / incomplete / wrong documentation is an old issue in IT - but i personally prefer fixes to bugs, as the best documentation will not help you if the product has issues...&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The gateways shouldn't even have these outdated ciphers enabled by default&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;--&amp;gt; I would suggest you do a RFE for that...&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 09:38:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187463#M34558</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-25T09:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187468#M34559</link>
      <description>&lt;P&gt;An RFE to remove Ciphers without PFS support and that use SHA-1?&amp;nbsp; They shouldn't be included on a security gateway in this day and age.&lt;/P&gt;&lt;P&gt;&lt;A href="https://ciphersuite.info/" target="_blank" rel="noopener"&gt;https://ciphersuite.info/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 10:07:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187468#M34559</guid>
      <dc:creator>Fire_Verse</dc:creator>
      <dc:date>2023-07-25T10:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187472#M34562</link>
      <description>&lt;P&gt;Feel free to raise this with your local Check Point representative.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 10:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187472#M34562</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-07-25T10:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 cipher_util issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187495#M34569</link>
      <description>&lt;P&gt;Could not agree more&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23046"&gt;@Fire_Verse&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:34:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-cipher-util-issue/m-p/187495#M34569</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-25T12:34:04Z</dc:date>
    </item>
  </channel>
</rss>

