<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Weak SSL ciphers in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103718#M30143</link>
    <description>Sorry, for the web page.  If possible I'd like to prevent the Insight Manager website from using weak encryption.</description>
    <pubDate>Fri, 16 Nov 2007 15:30:09 GMT</pubDate>
    <dc:creator>Rusty Williams</dc:creator>
    <dc:date>2007-11-16T15:30:09Z</dc:date>
    <item>
      <title>Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103716#M30141</link>
      <description>Can I configure Insight Manager 5.1 to avoid the use of weak SSL ciphers?  Thanks.</description>
      <pubDate>Thu, 15 Nov 2007 17:46:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103716#M30141</guid>
      <dc:creator>Rusty Williams</dc:creator>
      <dc:date>2007-11-15T17:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103717#M30142</link>
      <description>SSL cipher? for web page ,SNMP?&lt;BR /&gt;&lt;BR /&gt;Dan</description>
      <pubDate>Fri, 16 Nov 2007 12:36:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103717#M30142</guid>
      <dc:creator>Daniel Leblanc</dc:creator>
      <dc:date>2007-11-16T12:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103718#M30143</link>
      <description>Sorry, for the web page.  If possible I'd like to prevent the Insight Manager website from using weak encryption.</description>
      <pubDate>Fri, 16 Nov 2007 15:30:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103718#M30143</guid>
      <dc:creator>Rusty Williams</dc:creator>
      <dc:date>2007-11-16T15:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103719#M30144</link>
      <description>I am not sure but i have this web page that esplains the securite,&lt;BR /&gt;&lt;A href="http://www.docs.hp.com/en/418811-002/ch01s08.html" target="_blank"&gt;http://www.docs.hp.com/en/418811-002/ch01s08.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;PS:Don't ferget to apply you re points,there situated next to every message date and time as UNASSIGNED.&lt;BR /&gt;&lt;BR /&gt;Dan</description>
      <pubDate>Fri, 16 Nov 2007 15:39:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103719#M30144</guid>
      <dc:creator>Daniel Leblanc</dc:creator>
      <dc:date>2007-11-16T15:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103720#M30145</link>
      <description>Let me explain more.  I know that Insight Manager uses an embeded version of Tomcat.  In a normal tomcat install, you can configure the .conf files to customize your site.  I am wondering if I am able to access the conf files in the embeded tomcat.  If I can, then I can configure them to not allow SSLv2. &lt;BR /&gt;&lt;BR /&gt;Regarding points, which is better, low or high?</description>
      <pubDate>Fri, 16 Nov 2007 18:01:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103720#M30145</guid>
      <dc:creator>Rusty Williams</dc:creator>
      <dc:date>2007-11-16T18:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103721#M30146</link>
      <description>Always high ;)&lt;BR /&gt;&lt;BR /&gt;Dan</description>
      <pubDate>Mon, 19 Nov 2007 09:18:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103721#M30146</guid>
      <dc:creator>Daniel Leblanc</dc:creator>
      <dc:date>2007-11-19T09:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103722#M30147</link>
      <description>Sorry Rusty, tried to find somethings in these isue,not many people have wanted to go there, i have up upgrade the securite between the server,because if you look at the information between HP sim server and HP client(SNMP) it using V1,yerk  so i applied this way.&lt;BR /&gt;&lt;BR /&gt;it could be weak cypher at the level of the web server,but at least it got one ;),between the server insight and it client majorite don't use securite.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://support.microsoft.com/kb/324261/en-us" target="_blank"&gt;http://support.microsoft.com/kb/324261/en-us&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;i configure a template and applied it every where.&lt;BR /&gt;&lt;BR /&gt;Sorry can't help you if you get a final solution it would great if informe every body here,it will great.&lt;BR /&gt;&lt;BR /&gt;Thank you and have a nice day.&lt;BR /&gt;&lt;BR /&gt;Daniel</description>
      <pubDate>Mon, 19 Nov 2007 09:35:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103722#M30147</guid>
      <dc:creator>Daniel Leblanc</dc:creator>
      <dc:date>2007-11-19T09:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103723#M30148</link>
      <description>Rusty,&lt;BR /&gt;&lt;BR /&gt;I believe the file you are looking for is:&lt;BR /&gt;&lt;BR /&gt;C:\Program Files\HP\Systems Insight Manager\jboss\server\hpsim\deploy\jbossweb-tomcat50.sar\server.xml.&lt;BR /&gt;&lt;BR /&gt;In this file, there are 3 connectors defined for ports 50000, 50001 and 50002.&lt;BR /&gt;&lt;BR /&gt;The last variable in each connector line is 'sslProtocol="XXX".&lt;BR /&gt;&lt;BR /&gt;Here is a link to Apache Tomcat 5.5 and the SSL settings for it.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://tomcat.apache.org/tomcat-5.5-doc/ssl-howto.html" target="_blank"&gt;http://tomcat.apache.org/tomcat-5.5-doc/ssl-howto.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I can't tell you if simply defining a stronger sslProtcol will do what you want, since I am not willing to break my SIM installation trying. :)&lt;BR /&gt;&lt;BR /&gt;Also, I suspect any changes you make to this file will get overwritten during upgrades, etc..&lt;BR /&gt;&lt;BR /&gt;Good luck.</description>
      <pubDate>Mon, 19 Nov 2007 15:32:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103723#M30148</guid>
      <dc:creator>A. Edens</dc:creator>
      <dc:date>2007-11-19T15:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103724#M30149</link>
      <description>Thanks for the info. I had already poked my head around the server.xml file, but was afraid to make changes until I saw your post.  Here's what I found:  NOTHING WORKS.&lt;BR /&gt;&lt;BR /&gt;Our security team would like to prevent insight manager from using SSLv2.  I can't imagine just changing the ssl protocol from TLS to SSL would accomplish that.  I tried specifying SSLv3, but that prevented insight manager from working.  I also tried adding ciphers="blah,blah" where blah and blah equal different SSLv3 ciphers.  Again, it just prevented insight manager from loading. &lt;BR /&gt;&lt;BR /&gt;At this point, I've probably wasted too much time on this.  Unless someone posts something spectacularly insightful, I'm calling this a lost cause.&lt;BR /&gt;&lt;BR /&gt;Thanks for your help.</description>
      <pubDate>Mon, 19 Nov 2007 18:03:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103724#M30149</guid>
      <dc:creator>Rusty Williams</dc:creator>
      <dc:date>2007-11-19T18:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Weak SSL ciphers</title>
      <link>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103725#M30150</link>
      <description>I have just implemented this.  You are correct in the need to edit the servers.xml file.&lt;BR /&gt;&lt;BR /&gt;I added the ciphers field and value pair as follows:&lt;BR /&gt;ciphers="SSL_RSA_WITH_RC4_128_MD5"&lt;BR /&gt;&lt;BR /&gt;to the line:&lt;BR /&gt;&lt;BR /&gt;    &lt;CONNECTOR address="${jboss.bind.address}" port="50000" scheme="https" secure="true" maxthreads="200" minsparethreads="10" maxsparethreads="25" enablelookups="false" acceptcount="10" debug="5" uriencoding="utf-8" usebodyencodingforuri="true" clientauth="false" keystorefile="C:\Program Files\HP\Systems Insight Manager\config\certstor\hp.keystore" keystorepass="xxxxxxxxxxxxx" sslprotocol="TLS" ciphers="SSL_RSA_WITH_RC4_128_MD5"&gt;&lt;/CONNECTOR&gt;&lt;BR /&gt;&lt;BR /&gt;You can add additional ciphers but I was happy to go with one I knew was available on all admin workstations.</description>
      <pubDate>Tue, 16 Sep 2008 03:38:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/weak-ssl-ciphers/m-p/4103725#M30150</guid>
      <dc:creator>Phil McIlwraith</dc:creator>
      <dc:date>2008-09-16T03:38:11Z</dc:date>
    </item>
  </channel>
</rss>

