<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIC initialization still communicates over SSLv3 ? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229259#M38295</link>
    <description>&lt;P&gt;I've spoken to R&amp;amp;D owner and&amp;nbsp;SIC initialization uses TLS 1.2 in R81.10 and higher versions.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2024 10:51:13 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2024-10-09T10:51:13Z</dc:date>
    <item>
      <title>SIC initialization still communicates over SSLv3 ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229192#M38277</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;the sk107166 "TLS1.2 Support Plan for Check Point Products"&amp;nbsp; seems to be vallid&amp;nbsp; and maintained (Last modified&lt;BR /&gt;2023-09-11).&lt;BR /&gt;I find the note that the SIC initialization still communicates via ssl v3. Is this really the case and if so, why?&lt;/P&gt;&lt;P&gt;Of course it is only the initialization, but I am afraid that this is a topic that I have to discuss with our internal audit department and would like to avoid this &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 14:22:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229192#M38277</guid>
      <dc:creator>Herr_O</dc:creator>
      <dc:date>2024-10-08T14:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: SIC initialization still communicates over SSLv3 ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229196#M38278</link>
      <description>&lt;P&gt;R81.10 and higher:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk178505" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk178505&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TLS.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28032i8AC58DC04DE97FB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="TLS.png" alt="TLS.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Secure-Internal-Communication.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Secure-Internal-Communication.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TLS in SIC.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28033i21981D50D52DFC0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="TLS in SIC.png" alt="TLS in SIC.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 16:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229196#M38278</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-10-08T16:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: SIC initialization still communicates over SSLv3 ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229229#M38285</link>
      <description>&lt;P&gt;Thanks for the answer&lt;BR /&gt;I know the SIC communication, but my question refers explicitly to the SIC initialization&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;------&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk107166" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk107166&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Notes:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;The schedule can be subject to modifications. For most up-to-date information, revisit this page or subscribe to RSS feed (at the top).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Support for TLS 1.2 was integrated since&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Take 266&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106162" target="_blank" rel="noopener"&gt;R77.30 Jumbo Hotfix&lt;/A&gt;.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;The SIC initialization still communicates over SSLv3.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;For VSX Gateway, refer to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112014" target="_blank" rel="noopener"&gt;sk112014 - "Cannot establish connection to SSL Network Extender gateway. Try to reconnect." error when connecting with SSL Network Extender to Mobile Access Portal on VSX Virtual System after installing the "TLS 1.2 Hotfix for R77.30"&lt;/A&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Before installing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Take 266&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and higher of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106162" target="_blank" rel="noopener"&gt;R77.30 Jumbo Hotfix&lt;/A&gt;, make sure to back up&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;all&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the current&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;httpd.conf&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;files:&lt;BR /&gt;&lt;EM&gt;[Expert@HostName:0]# find / -name httpd.conf -type f&lt;/EM&gt;&lt;/P&gt;If any changes were made in the past in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;httpd.conf&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;files, then the new&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;httpd.conf&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;files should be edited manually (do NOT overwrite the new files with the backed up files).&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If a connection from a SmartConsole computer to a Security Management Server / Domain Management Server must also be TLS 1.2, then an improved SmartConsole can be provided (otherwise, the communication will be TLS 1.0).&lt;/P&gt;This requires&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Take 266&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and higher of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106162" target="_blank" rel="noopener"&gt;R77.30 Jumbo Hotfix&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to be installed on the Security Management Server / Multi-Domain Security Management Server.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 09 Oct 2024 06:40:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229229#M38285</guid>
      <dc:creator>Herr_O</dc:creator>
      <dc:date>2024-10-09T06:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: SIC initialization still communicates over SSLv3 ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229238#M38288</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110433"&gt;@Herr_O&lt;/a&gt;&amp;nbsp;You are looking into the older SK, while&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;provided you with the updated information. Initialization is part of SIC, so&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178505" target="_blank" rel="noopener noreferrer"&gt;sk178505&lt;/A&gt;&amp;nbsp;applies.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now, if you need a stumped official response you could use for the audit, it is advisable to open a TAC ticket for 100% official answer.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 08:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229238#M38288</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-10-09T08:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: SIC initialization still communicates over SSLv3 ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229259#M38295</link>
      <description>&lt;P&gt;I've spoken to R&amp;amp;D owner and&amp;nbsp;SIC initialization uses TLS 1.2 in R81.10 and higher versions.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 10:51:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-initialization-still-communicates-over-SSLv3/m-p/229259#M38295</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-10-09T10:51:13Z</dc:date>
    </item>
  </channel>
</rss>

