<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Server Has SSLv2 Enabled Vulnerability in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602942#M55341</link>
    <description>&lt;P&gt;SSL Server Has SSLv2 Enabled Vulnerability port 2381/tcp over SSL &lt;BR /&gt;&lt;BR /&gt;Is the a way to mitigate this by going to SSLv3? I assume this is referring to Systems Manager.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. This thread has been moved&amp;nbsp;from ITRC server mgmt (Insight Manager 7) Forum to ITRC HP Systems Insight Manager Forum - HP Forums Moderator&lt;/P&gt;</description>
    <pubDate>Fri, 28 Dec 2012 02:28:41 GMT</pubDate>
    <dc:creator>Dave K.</dc:creator>
    <dc:date>2012-12-28T02:28:41Z</dc:date>
    <item>
      <title>SSL Server Has SSLv2 Enabled Vulnerability</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602942#M55341</link>
      <description>&lt;P&gt;SSL Server Has SSLv2 Enabled Vulnerability port 2381/tcp over SSL &lt;BR /&gt;&lt;BR /&gt;Is the a way to mitigate this by going to SSLv3? I assume this is referring to Systems Manager.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. This thread has been moved&amp;nbsp;from ITRC server mgmt (Insight Manager 7) Forum to ITRC HP Systems Insight Manager Forum - HP Forums Moderator&lt;/P&gt;</description>
      <pubDate>Fri, 28 Dec 2012 02:28:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602942#M55341</guid>
      <dc:creator>Dave K.</dc:creator>
      <dc:date>2012-12-28T02:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Server Has SSLv2 Enabled Vulnerability</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602943#M55342</link>
      <description>The software on port 2381 supports both SSLv2 and SSLv3.&lt;BR /&gt;&lt;BR /&gt;-Rich</description>
      <pubDate>Tue, 16 Aug 2005 11:06:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602943#M55342</guid>
      <dc:creator>Rich Purvis</dc:creator>
      <dc:date>2005-08-16T11:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Server Has SSLv2 Enabled Vulnerability</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602944#M55343</link>
      <description>How do you disable v2 so that only v3 is enabled?</description>
      <pubDate>Tue, 16 Aug 2005 11:12:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602944#M55343</guid>
      <dc:creator>Dave K.</dc:creator>
      <dc:date>2005-08-16T11:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Server Has SSLv2 Enabled Vulnerability</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602945#M55344</link>
      <description>I have the following security vulnerabilities on several hundred proliant servers. &lt;BR /&gt;&lt;BR /&gt;- SSL Server Supports Weak Encryption&lt;BR /&gt;- SSL Server Uses Weak Encryption&lt;BR /&gt;- SSL Server Has SSLv2 Enabled&lt;BR /&gt;- SSL Certificate - Signature Verification Failed&lt;BR /&gt;- SSL Certificate - Self-Signed Certificate&lt;BR /&gt;- SSL Certificate - Subject Common Name Does Not Match Server FQDN&lt;BR /&gt;&lt;BR /&gt;All of them are caused by the HP System Management Homepage (v2.0.1.104) which listens on SSL port 2381. Is there a way to enable SSLv3 and turn-off SSLv2 and also restrict access to strong encryption only?&lt;BR /&gt;&lt;BR /&gt;I got stuck and it seams it is not possible to disable v2. My attempts to change the config file "C:\hp\hpsmh\conf\smhpd.confâ   was without success. The file gets dumped when the SysMgmtHP service starts up. Therefore, I assume configuration settings are hard coded somewhere. &lt;BR /&gt;&lt;BR /&gt;A look at the SSLCipherSuite entry shows that v2 is enabled.&lt;BR /&gt;SSLCipherSuite ALL:!ADH:!EXPORT56:!EXPORT40:RC4+RSA:+HIGH:+MEDIUM:+SSLv2:+EXP:-LOW:+eNULL&lt;BR /&gt;&lt;BR /&gt;This should be changed to: &lt;BR /&gt;SSLCipherSuite ALL:!ADH:!EXPORT56:!EXPORT40:RC4+RSA:+HIGH:+MEDIUM:-SSLv2:+SSLv3:+EXP:-LOW:+eNULL&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Mon, 05 Sep 2005 13:39:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602945#M55344</guid>
      <dc:creator>Josef Roth_2</dc:creator>
      <dc:date>2005-09-05T13:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Server Has SSLv2 Enabled Vulnerability</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602946#M55345</link>
      <description>I get the same SSLv2 Enabled Vulnerability. How can this be mitigated? This is in reference to the HP System Management Homepage. When I disable this service the SSLv2 vulnerability is removed, the only problem is that we use the system management homepage. Thanks</description>
      <pubDate>Mon, 04 Dec 2006 10:22:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602946#M55345</guid>
      <dc:creator>ekonop</dc:creator>
      <dc:date>2006-12-04T10:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Server Has SSLv2 Enabled Vulnerability</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602947#M55346</link>
      <description>Latest versions of System Mangement Homepage have SSL V2 disabled by default. I would suggest you upgrade to the latest version.&lt;BR /&gt;&lt;BR /&gt;-Rich</description>
      <pubDate>Wed, 06 Dec 2006 17:15:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-server-has-sslv2-enabled-vulnerability/m-p/3602947#M55346</guid>
      <dc:creator>Rich Purvis</dc:creator>
      <dc:date>2006-12-06T17:15:22Z</dc:date>
    </item>
  </channel>
</rss>

