Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gaurav_Pandya
Advisor

SSH Server and Gaia Portal Cipher Configuration Guide

I realized that it would be beneficial to create a single consolidated document covering the procedures for enabling and disabling ciphers across different portals and servers. This way, users can refer to one unified source for all cipher‑related configurations.

1. Ciphers for SSH Server
Please refer to the following URL for enabling/disabling ciphers for the SSH server:
https://community.checkpoint.com/t5/General-Topics/How-to-edit-modify-weak-ciphers-for-SSH-server/m-...

2. Correcting "Invalid SSL/TLS Protocol & Ciphers" for Gaia Portal
Run the following commands:
• cd /web/templates
• ls -la h* <-- list files
• cp /web/templates/httpd-ssl.conf.templ /web/templates/httpd-ssl.conf.templ_BKP2 <-- Backup the file
• vi /web/templates/httpd-ssl.conf.templ <-- edit the file
Configuration Changes
Update the SSLCipherSuite line as required:
SSLCipherSuite ECDH:!aNULL:!ECDSA:!aECDH:!eNULL:!MD5:!SHA1:!CAMELLIA
Update the SSLProtocol line as required
SSLProtocol -ALL {ifcmp = $httpd:ssl3_enabled 1}+{else}-{endif}SSLv3 +TLSv1.2 (remove +TLS1.0 and TLS1.1)
Restart the Process
• tellpm process:httpd2
• tellpm process:httpd2 t

3. Using cipher_util Tool for Security Gateways
Refer to sk126613 to manage ciphers using the cipher_util tool.

0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events