<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic In Wildfire how do we disable weak TLS ciphers? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/in-wildfire-how-do-we-disable-weak-tls-ciphers/m-p/513209#M106622</link>
    <description>&lt;P&gt;Nessus scanning is picking up TCP/443 TLS v1.0 and v1.1 on our WildFire (WF-500) appliances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is there a way to turn off TLS v1.0 and v1.1 on the WildFire ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Below is the Nessus scanner notification.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Violation 443/tcp Nessus ID: 56984&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Synopsis :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The remote service encrypts communications.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Description :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This plugin detects which SSL and TLS versions are supported by the&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;remote service for encrypting communications.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See also :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Solution :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;n/a&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Risk factor :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;None / CVSS Base Score :0.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Prioritized Risk :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;None (VPR: n/a / CVSS v3: None / CVSS v2: None)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Plugin output :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This port supports TLSv1.0/TLSv1.1/TLSv1.2.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Aug 2022 01:49:52 GMT</pubDate>
    <dc:creator>pjohnson1</dc:creator>
    <dc:date>2022-08-29T01:49:52Z</dc:date>
    <item>
      <title>In Wildfire how do we disable weak TLS ciphers?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-wildfire-how-do-we-disable-weak-tls-ciphers/m-p/513209#M106622</link>
      <description>&lt;P&gt;Nessus scanning is picking up TCP/443 TLS v1.0 and v1.1 on our WildFire (WF-500) appliances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is there a way to turn off TLS v1.0 and v1.1 on the WildFire ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Below is the Nessus scanner notification.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Violation 443/tcp Nessus ID: 56984&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Synopsis :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The remote service encrypts communications.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Description :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This plugin detects which SSL and TLS versions are supported by the&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;remote service for encrypting communications.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See also :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Solution :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;n/a&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Risk factor :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;None / CVSS Base Score :0.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Prioritized Risk :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;None (VPR: n/a / CVSS v3: None / CVSS v2: None)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Plugin output :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This port supports TLSv1.0/TLSv1.1/TLSv1.2.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 01:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-wildfire-how-do-we-disable-weak-tls-ciphers/m-p/513209#M106622</guid>
      <dc:creator>pjohnson1</dc:creator>
      <dc:date>2022-08-29T01:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: In Wildfire how do we disable weak TLS ciphers?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-wildfire-how-do-we-disable-weak-tls-ciphers/m-p/513334#M106641</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see the article below and set the min TLS version you want:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/set-up-and-manage-a-wildfire-appliance/set-up-authentication-using-custom-certs-standalone-wildfire-appliance/configure-authentication-with-custom-certificates-on-wf-500" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/set-up-and-manage-a-wildfire-appliance/set-up-authentication-using-custom-certs-standalone-wildfire-appliance/configure-authentication-with-custom-certificates-on-wf-500&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;UL&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class="" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class="" data-label="NOTE"&gt;
&lt;DIV&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class=""&gt;
&lt;DIV style="display: inline;"&gt;PAN-OS 8.0 and later releases support TLS 1.2 and later TLS versions only. You must set the max version to TLS 1.2 or max.
&lt;DIV class="" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;admin@WF-500#
&lt;DIV style="display: inline;"&gt;set shared ssl-tls-service-profile
&lt;DIV style="display: inline;"&gt;&amp;lt;name&amp;gt;protocol-settings min-version {tls1-0 | tls1-1 | tls1-2}
&lt;DIV class="" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;admin@WF-500#
&lt;DIV style="display: inline;"&gt;set shared ssl-tls-service-profile
&lt;DIV style="display: inline;"&gt;&amp;lt;name&amp;gt;protocol-settings max-version {tls1-0 | tls1-1 | tls1-2 | max}&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;Configure secure server communication on the WildFire appliance.
&lt;DIV style="display: inline;"&gt;
&lt;UL&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;Set the SSL/TLS profile. This SSL/TLS service profile applies to all SSL connection between WildFire and client devices.
&lt;DIV class="" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;admin@WF-500#
&lt;DIV style="display: inline;"&gt;set deviceconfig setting management secure-conn-server ssl-tls-service-profile
&lt;DIV style="display: inline;"&gt;&amp;lt;ssltls-profile&amp;gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class="" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class="" data-label="NOTE"&gt;
&lt;DIV&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class="" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class="" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 30 Aug 2022 06:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-wildfire-how-do-we-disable-weak-tls-ciphers/m-p/513334#M106641</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-08-30T06:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: In Wildfire how do we disable weak TLS ciphers?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-wildfire-how-do-we-disable-weak-tls-ciphers/m-p/1220622#M123288</link>
      <description>&lt;P&gt;how does this disable weak ciphers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 06:35:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-wildfire-how-do-we-disable-weak-tls-ciphers/m-p/1220622#M123288</guid>
      <dc:creator>S.Ramesh960545</dc:creator>
      <dc:date>2025-02-17T06:35:47Z</dc:date>
    </item>
  </channel>
</rss>

