<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186812#M31215</link>
    <description>&lt;P&gt;As per the attached screen shot, we are already on TLS1.2, but still getting the above vulnerability on scan report.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 09:25:09 GMT</pubDate>
    <dc:creator>Bachan</dc:creator>
    <dc:date>2023-07-19T09:25:09Z</dc:date>
    <item>
      <title>Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186739#M31195</link>
      <description>&lt;P&gt;Host : Management Server(SMS)&lt;/P&gt;&lt;P&gt;OS : R80.40&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port:8211&lt;/P&gt;&lt;P&gt;Vulnerability_ID :ssl-weak-message-authentication-code-algorithms&lt;/P&gt;&lt;P&gt;Vulnerability_NAME :&amp;nbsp;TLS/SSL Weak Message Authentication Code Cipher Suites&lt;/P&gt;&lt;P&gt;Vulnerability_Proof:&amp;nbsp;Negotiated with the following insecure cipher suites:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * TLS 1.2 ciphers:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; * TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * TLS_RSA_WITH_AES_128_CBC_SHA&lt;/P&gt;&lt;P&gt;Vulnerability_Solution:&amp;nbsp;Disable any weak HMAC algorithms within the TLS configurationThe following recommended configuration provides a higher level of security. This configuration is compatible with Firefox 27; Chrome 22; IE 11; Opera 17 and Safari 9. SSLv2; SSLv3; TLSv1 and TLSv1.1 protocols are not recommended in this configuration. Instead use TLSv1.2 protocol.Refer to your server vendor documentation to apply the recommended cipher configuration:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK:!SHA1:!DSS&lt;/P&gt;&lt;P&gt;Port 8211 uses TLS 1.2 .Attached file for reference.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;We have checked the sshd.config file httpd all looks fine . Can you please let us know what needs to be tweaked here?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 18:15:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186739#M31195</guid>
      <dc:creator>Bachan</dc:creator>
      <dc:date>2023-07-18T18:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186772#M31203</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk168472" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk168472&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 21:08:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186772#M31203</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-18T21:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186812#M31215</link>
      <description>&lt;P&gt;As per the attached screen shot, we are already on TLS1.2, but still getting the above vulnerability on scan report.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 09:25:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186812#M31215</guid>
      <dc:creator>Bachan</dc:creator>
      <dc:date>2023-07-19T09:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186895#M31231</link>
      <description>&lt;P&gt;Recommend engaging with the TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186895#M31231</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-19T17:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186897#M31232</link>
      <description>&lt;P&gt;I was going to suggest same sk as Phoneboy, but since you said its already on TLS 1.2, then best to contact TAC to verify.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:19:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186897#M31232</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T17:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186900#M31234</link>
      <description>&lt;P&gt;Can you confirm how below is set in global properties?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21795i80188E346E6A4D7A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:22:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186900#M31234</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T17:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186902#M31235</link>
      <description>&lt;P&gt;Both are set to TLS 1.2 .&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:24:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186902#M31235</guid>
      <dc:creator>Bachan</dc:creator>
      <dc:date>2023-07-19T17:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186905#M31237</link>
      <description>&lt;P&gt;Then I would say contact TAC, for sure.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:25:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186905#M31237</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T17:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186908#M31239</link>
      <description>&lt;P&gt;Please let us know what they say, as the answer can help others with the same issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:39:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/186908#M31239</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T17:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability-ssl-weak-message-authentication-code-algorithms for Port 8211</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/201470#M33578</link>
      <description>&lt;P&gt;Kindly please refers to&amp;nbsp;&lt;SPAN&gt;sk181683 and a hotfix is needed to disable the&amp;nbsp;weak HMAC&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;algorithms&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181683" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181683&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Dec 2023 02:38:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-ssl-weak-message-authentication-code-algorithms/m-p/201470#M33578</guid>
      <dc:creator>Wei_Zhang</dc:creator>
      <dc:date>2023-12-25T02:38:46Z</dc:date>
    </item>
  </channel>
</rss>

