<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get better grades in the SSL Labs Cert. scan in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25513#M13219</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's a start:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774"&gt;Vulnerability scan shows that there are weak ciphers related to TLS 1.2&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 09 Sep 2018 07:30:12 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-09-09T07:30:12Z</dc:date>
    <item>
      <title>How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25512#M13218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can any one here guide me on how to get a better score when I scan my firewall with the&amp;nbsp;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html" title="https://www.ssllabs.com/ssltest/analyze.html"&gt;SSL Server Test (Powered by Qualys SSL Labs)&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a quick guide on how to enable forward secrecy, disable tls v1.0, 1.1 and weak ciphers etc. ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;IMG __jive_id="70108" alt="Qualys SSL Scan" class="image-1 jive-image" height="355" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70108_spg1.PNG" width="584" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp; Best regards Keld Norman&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;Thanks for the anwsers so far - I have collected them all - testet and gotten better scores - here is what i did:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#######################################################################&lt;/P&gt;&lt;P&gt;#&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; HOW TO GET BETTER GRADES IN THE SSLLABS.COM SSL TEST&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/P&gt;&lt;P&gt;#######################################################################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To get from the B to A I did the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 22px;"&gt;Alter the portal to only support TLS 1.2&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;In my 80.10 SmartConsole:&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;&amp;nbsp; Global Properties -&amp;gt;&amp;nbsp;AdvancedConfiguration -&amp;gt; Portal Properties:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;SPAN style="color: #ff00ff;"&gt;Altered minimum version to TLS 1.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="70139" alt="TLS" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70139_tls.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11px; color: #808080;"&gt;NB: Thanks to Claus Kjær for reminding me of this GUI way of doing things - I were trying to do achieve this by altering conf files with vim in expert shell..&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 22px;"&gt;Now to enable perfect forward support:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;REF:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110883" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110883"&gt;Specific HTTPS sites that use ECDHE ciphers are not accessible when HTTPS Inspection is enabled&lt;/A&gt;&amp;nbsp;(sk110883)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH&gt;A note about the above&amp;nbsp;sk110883&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13px;"&gt;&lt;EM&gt;&lt;SPAN style="color: #242729; background: white;"&gt;&lt;STRONG&gt;ECDHE&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #242729; background: white;"&gt;&amp;nbsp;is quite widely used and recommend. It works with elliptical keys and&amp;nbsp;&lt;A href="https://security.stackexchange.com/questions/33233/ecdh-and-forward-secrecy"&gt;&lt;SPAN style="color: #1b608a;"&gt;provides forward secrecy&lt;/SPAN&gt;&lt;/A&gt;. It's used for the key exchange.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="color: #242729; background: white; font-size: 13px;"&gt;&lt;EM&gt;&lt;A href="https://security.stackexchange.com/questions/58603/are-any-major-websites-offering-ecdsa-authentication"&gt;&lt;SPAN style="color: #1b608a;"&gt;&lt;STRONG&gt;ECDSA&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #1b608a;"&gt;&amp;nbsp;is not widely used&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;though, but it does also use elliptical keys. It it used for authentication&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I logged on to the firewall via secure shell&amp;nbsp; (I have a standalone installation with the manager and firewall running in a VM) and in expert mode pasted the following 3 lines in:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #999999;"&gt;[Expert@firewall:0]#&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff00ff;"&gt;ckp_regedit -a SOFTWARE//CheckPoint//FW1 CPTLS_ACCEPT_ECDHE 1 &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff00ff;"&gt;ckp_regedit -a SOFTWARE//CheckPoint//FW1 CPTLS_PROPOSE_ECDHE 1 &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff00ff;"&gt;ckp_regedit -a SOFTWARE//CheckPoint//FW1 CPTLS_EC_P384 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then a reboot or just a cpstop/start is needed:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff00ff;"&gt;&lt;SPAN style="color: #999999;"&gt;[Expert@firewall:0]#&amp;nbsp;&lt;/SPAN&gt; &amp;nbsp;nohup $(cpstop ; cpstart) &amp;amp;&lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN style="color: #000000;"&gt;Now the grade went from B to A :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="70140" alt="SSLlabs scanning went from B to A rating" class="image-3 jive-image" height="194" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70140_scan_a.PNG" width="403" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now to look at the suggested link from&amp;nbsp;&lt;A _jive_internal="true" class="" data-userid="2075" data-username="dwelccfe6e688-522c-305c-adaa-194bd7a7becc" href="https://community.checkpoint.com/people/dwelccfe6e688-522c-305c-adaa-194bd7a7becc" style="color: #e45785; background-color: #ffffff; border: 0px; font-weight: 200; text-decoration: none; font-size: 1.286rem;"&gt;Dameon Welch Abernathy&lt;/A&gt;&lt;SPAN style="color: #e45785; background-color: #ffffff; font-weight: 500;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;IMG alt="Employee" class="" height="16" style="color: #e45785; background-color: #ffffff; border: 0px; font-weight: 500; font-size: 10.9998px; margin: 0px 2px -3px -1px;" title="Employee" width="16" /&gt;&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;BR /&gt;Remove the weak ciphers related to TLS 1.2&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;(ref:&amp;nbsp;&lt;A class="jivelink1" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically I just need to alter this in the file:&amp;nbsp;&lt;SPAN&gt;/web/templates/httpd-ssl.conf.templ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ALTER: &lt;SPAN style="color: #ff0000;"&gt;SSLCipherSuite HIGH:!RC4:!LOW:!EXP:!aNULL:!SSLv2:!MD5&lt;/SPAN&gt;&lt;BR /&gt;TO &lt;SPAN style="color: #339966;"&gt;SSLCipherSuite ECDH:!aNULL:!ECDSA:!aECDH:!eNULL:!MD5:!SHA1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again secure shell to the system - and in export mode paste the lines in purple below:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# Backup the file you want to alter first&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #999999;"&gt;[Expert@firewall:0]#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;cp /web/templates/httpd-ssl.conf.templ /web/templates/httpd-ssl.conf.templ.backup&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# Oneliner to replace the old line with the new using the SED util.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;&lt;BR /&gt;sed -i 's/SSLCipherSuite HIGH:!RC4:!LOW:!EXP:!aNULL:!SSLv2:!MD5/SSLCipherSuite ECDH:!aNULL:!ECDSA:!aECDH:!eNULL:!MD5:!SHA1/' /web/templates/httpd-ssl.conf.templ &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;# Test if the line was altered:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;grep -i ^SSLCipherSuite /web/templates/httpd-ssl.conf.templ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;( it should return:&amp;nbsp;&lt;SPAN style="color: #339966;"&gt;SSLCipherSuite ECDH:!aNULL:!ECDSA:!aECDH:!eNULL:!MD5:!SHA1&lt;/SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then reboot the firewall..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="color: #999999;"&gt;[Expert@firewall:0]#&lt;/SPAN&gt; &lt;SPAN style="color: #ff00ff;"&gt;reboot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d;"&gt;The Qualys SSL scan still only shows an A - I still have some weak ciphers &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d;"&gt;&lt;IMG __jive_id="70142" alt="Weak ciphers.." class="image-4 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70142_weak-ciphers.PNG" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d;"&gt;To be continued..&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2018 14:19:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25512#M13218</guid>
      <dc:creator>Keld_Norman</dc:creator>
      <dc:date>2018-09-07T14:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades in the SSL Labs Cert. scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25513#M13219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's a start:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774"&gt;Vulnerability scan shows that there are weak ciphers related to TLS 1.2&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Sep 2018 07:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25513#M13219</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-09T07:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25514#M13220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was a good tip - I'll just need to investigate what impact disabling the last 4 weak ciphers would have if i turn them off:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE style="background-color: #fdfdfd; font-size: 12px; margin: 0px 10px 0px 0px;"&gt;&lt;THEAD&gt;&lt;TR&gt;&lt;TD class="" colspan="3" style="color: #009ddf; border-bottom: 2px solid #c6d2d4; font-weight: bold; font-size: 13px; padding-bottom: 5px;"&gt;Cipher Suites&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR class=""&gt;&lt;TD class="" colspan="3" style="color: #009ddf; border-bottom: 1px solid #c6d2d4; font-weight: bold; font-size: 12px; padding-top: 15px; padding-bottom: 5px;"&gt;&lt;SPAN class=""&gt;&lt;IMG height="14" src="https://www.ssllabs.com/images/collapse.png" style="border: none;" width="14" /&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;# TLS 1.2 (suites in server-preferred order)&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;TBODY class=""&gt;&lt;TR class=""&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN class="" style="color: green !important;"&gt;TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (&lt;CODE&gt;0xc02f&lt;/CODE&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="color: #666666 !important; font-size: 10px;"&gt;ECDH secp256r1 (eq. 3072 bits RSA) &amp;nbsp; FS&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;128&lt;/TD&gt;&lt;/TR&gt;&lt;TR class=""&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (&lt;CODE&gt;0xc014&lt;/CODE&gt;) &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="color: #666666 !important; font-size: 10px;"&gt;ECDH secp256r1 (eq. 3072 bits RSA) &amp;nbsp; FS&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;256&lt;/TD&gt;&lt;/TR&gt;&lt;TR class=""&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (&lt;CODE&gt;0xc013&lt;/CODE&gt;) &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="color: #666666 !important; font-size: 10px;"&gt;ECDH secp256r1 (eq. 3072 bits RSA) &amp;nbsp; FS&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;128&lt;/TD&gt;&lt;/TR&gt;&lt;TR class=""&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;TLS_RSA_WITH_AES_128_GCM_SHA256 (&lt;CODE&gt;0x9c&lt;/CODE&gt;) &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WEAK&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;128&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class=""&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;TLS_RSA_WITH_AES_128_CBC_SHA (&lt;CODE&gt;0x2f&lt;/CODE&gt;) &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WEAK&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;128&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class=""&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;TLS_RSA_WITH_AES_256_CBC_SHA (&lt;CODE&gt;0x35&lt;/CODE&gt;) &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WEAK&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;256&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class=""&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;TLS_RSA_WITH_3DES_EDE_CBC_SHA (&lt;CODE&gt;0xa&lt;/CODE&gt;) &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WEAK&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="" style="border-bottom: 1px solid #f0f0f0; padding: 3px 0px;"&gt;&lt;SPAN style="color: #f88017;"&gt;112&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2018 10:04:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25514#M13220</guid>
      <dc:creator>Keld_Norman</dc:creator>
      <dc:date>2018-09-10T10:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25515#M13221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should probably add&amp;nbsp;!3DES to the list of modifications as well.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2018 14:16:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/25515#M13221</guid>
      <dc:creator>Alex_Weldon</dc:creator>
      <dc:date>2018-09-10T14:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/52935#M13222</link>
      <description>&lt;P&gt;One vulnerability scan shows we have weak dh groups. We don't use those groups...but it doesn't like the fact that we even have them available...? How would one go about fixing that.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 17:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/52935#M13222</guid>
      <dc:creator>Trey_Havener</dc:creator>
      <dc:date>2019-05-08T17:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/58362#M13223</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Just to revive this old post, this SK is relevant for versions R80.10, R80.20 and R80.30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="cp_h2_black"&gt;Cipher configuration tool for R80.x Gateways&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&lt;SPAN&gt;sk126613&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&lt;SPAN&gt;Just used this on a customer and works as advertised.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&lt;SPAN&gt;Have fun,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&lt;SPAN&gt;Pedro Madeira&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="cp_link_block"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 16 Jul 2019 16:25:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/58362#M13223</guid>
      <dc:creator>Pedro_Madeira</dc:creator>
      <dc:date>2019-07-16T16:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/59672#M13224</link>
      <description>&lt;P&gt;The SSLLABS scan still show the weak ciphers.&lt;/P&gt;&lt;P&gt;Can we remove all the ciphers except one that is shown ok?&lt;/P&gt;&lt;P&gt;How about preferring PFS ciphers?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 19:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/59672#M13224</guid>
      <dc:creator>An_Nguyen</dc:creator>
      <dc:date>2019-08-05T19:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/59897#M13225</link>
      <description>&lt;P&gt;Nice tutorial!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Waiting for part 2.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 15:43:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/59897#M13225</guid>
      <dc:creator>rovame2013</dc:creator>
      <dc:date>2019-08-08T15:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/66794#M13228</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all thanks for sharing your investigation, i used some of your findings in my own lab for testing purposes. Could you explain to me if you're trying to get a better grade for your "Multiportal" (Gaia Web Interface) or are you trying to get a better grade for a website that is terminated via HTTPS inspection on your gateway?&lt;/P&gt;&lt;P&gt;I am in a situation where i need to enhance the ciphers proposed when using inbound HTTPS inscpection on&lt;STRONG&gt; R80.10&lt;/STRONG&gt;. What i discovered so far is that on R80.10 you can only alter the server preferred cipher order (The server is your Security Gateway), and it is not possible to disable some of the weak ciphers completely.&lt;/P&gt;&lt;P&gt;You are saying that you successfully disabled the weak ciphers if i understand correctly right? If so, does your customer run R80.20 or R80.30?&lt;/P&gt;&lt;P&gt;Because the SK (sk126613) describes the following under the section &lt;STRONG&gt;R80.10&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Important Information:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If a cipher exists in the file but the Security Gateway doesn't support it, the cipher will be ignored.&lt;/LI&gt;&lt;LI&gt;If there are ciphers on the Security Gateway that are not in the file, the Security Gateway will still use them but give preference to the ciphers in the file.&lt;/LI&gt;&lt;LI&gt;If there is a syntax error in the file, the changes will not take effect, and the Security Gateway will use the old behavior.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;This procedure is not relevant for SSL Inspection.&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I am still investigating so if i discover a way to disable the weak ciphers on R80.10 completely i will share this info with you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jelle&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 16:52:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/66794#M13228</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2019-11-07T16:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to get better grades @ SSL Labs Certificate scan</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/103944#M13229</link>
      <description>&lt;P&gt;Hi I am also facing similar issues on R80.10, specifically to disable&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (TLS_RSA_WITH_AES_128_GCM_SHA256)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (TLS_RSA_WITH_AES_128_CBC_SHA)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;: (TLS_RSA_WITH_AES_256_CBC_SHA)&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 03:01:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-get-better-grades-SSL-Labs-Certificate-scan/m-p/103944#M13229</guid>
      <dc:creator>nolankam</dc:creator>
      <dc:date>2020-12-02T03:01:59Z</dc:date>
    </item>
  </channel>
</rss>

