<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HP SIM and TLS1.0/1.1 in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7200846#M62689</link>
    <description>&lt;P dir="auto" style="margin: 0;"&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;The command "mxcipher -d" can be used to list what ciphers are in effect. Please check this first.We can get the ciphers used by SIM running command mxcipher –d. As per the update, we need to make SIM to use only ciphers showing TLSv1.2.Follow the actions below:&amp;lt;&amp;lt; Take a Valid Backup before making changes.1. Stop HPE SIM services.&amp;nbsp; msxtop&lt;BR /&gt;2. Make a secure copy of &amp;lt;SIM Install Directory&amp;gt;\Config\SecuritySettings.props.&lt;BR /&gt;3. Edit the file SecuritySettings.props then set as below&lt;BR /&gt;CIPHERS-USER=TLS_RSA_WITH_AES_128_CBC_SHA256&amp;nbsp; for example&lt;BR /&gt;4. Save the file.&lt;BR /&gt;5. Run the command mxcipher –e 2 which will update the cipher suites.&lt;BR /&gt;6. Restart HPE SIM services. mxstart&lt;BR /&gt;7. Run the command mxcipher –d which should show the selected ciphers are being used.After doing these changes SIM should be running only with TLSv1.2.Note:HPE SIM default ciphers are being used.&lt;BR /&gt;1. TLS_RSA_WITH_AES_128_CBC_SHA256 &amp;lt;&amp;lt; tls1.2&lt;BR /&gt;2. TLS_RSA_WITH_AES_256_CBC_SHA&amp;nbsp; &amp;lt;&amp;lt; tls1.0&lt;BR /&gt;3. TLS_RSA_WITH_AES_128_CBC_SHA &amp;lt;&amp;lt; tls 1.0&lt;BR /&gt;4. SSL_RSA_WITH_RC4_128_MD5&amp;nbsp; &amp;lt;&amp;lt; tls1.0&lt;BR /&gt;5. SSL_RSA_WITH_RC4_128_SHA &amp;lt;&amp;lt; tls1.2&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2023 16:15:18 GMT</pubDate>
    <dc:creator>BPSingh</dc:creator>
    <dc:date>2023-11-15T16:15:18Z</dc:date>
    <item>
      <title>HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7200283#M62684</link>
      <description>&lt;P&gt;Is it possible to configure HP SIM to NOT use TLS1.0 and TLS1.1?&amp;nbsp; Our internal security team is pressuring us to "remediate the TLS vulnerability on your system" before November 10th.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 05:43:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7200283#M62684</guid>
      <dc:creator>Ted Wood</dc:creator>
      <dc:date>2023-11-22T05:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7200846#M62689</link>
      <description>&lt;P dir="auto" style="margin: 0;"&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;The command "mxcipher -d" can be used to list what ciphers are in effect. Please check this first.We can get the ciphers used by SIM running command mxcipher –d. As per the update, we need to make SIM to use only ciphers showing TLSv1.2.Follow the actions below:&amp;lt;&amp;lt; Take a Valid Backup before making changes.1. Stop HPE SIM services.&amp;nbsp; msxtop&lt;BR /&gt;2. Make a secure copy of &amp;lt;SIM Install Directory&amp;gt;\Config\SecuritySettings.props.&lt;BR /&gt;3. Edit the file SecuritySettings.props then set as below&lt;BR /&gt;CIPHERS-USER=TLS_RSA_WITH_AES_128_CBC_SHA256&amp;nbsp; for example&lt;BR /&gt;4. Save the file.&lt;BR /&gt;5. Run the command mxcipher –e 2 which will update the cipher suites.&lt;BR /&gt;6. Restart HPE SIM services. mxstart&lt;BR /&gt;7. Run the command mxcipher –d which should show the selected ciphers are being used.After doing these changes SIM should be running only with TLSv1.2.Note:HPE SIM default ciphers are being used.&lt;BR /&gt;1. TLS_RSA_WITH_AES_128_CBC_SHA256 &amp;lt;&amp;lt; tls1.2&lt;BR /&gt;2. TLS_RSA_WITH_AES_256_CBC_SHA&amp;nbsp; &amp;lt;&amp;lt; tls1.0&lt;BR /&gt;3. TLS_RSA_WITH_AES_128_CBC_SHA &amp;lt;&amp;lt; tls 1.0&lt;BR /&gt;4. SSL_RSA_WITH_RC4_128_MD5&amp;nbsp; &amp;lt;&amp;lt; tls1.0&lt;BR /&gt;5. SSL_RSA_WITH_RC4_128_SHA &amp;lt;&amp;lt; tls1.2&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 16:15:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7200846#M62689</guid>
      <dc:creator>BPSingh</dc:creator>
      <dc:date>2023-11-15T16:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7200853#M62690</link>
      <description>&lt;P&gt;I am able to change the cipher suite to "&lt;SPAN&gt;TLS_RSA_WITH_AES_128_CBC_SHA256" but when I try to open HP SIM I get a message "ERR_SSL_VERSION_OR_CIPHER_MISMATCH".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;These are the cipher suites supported by my machine and&amp;nbsp;"TLS_RSA_WITH_AES_128_CBC_SHA256" is among them.&amp;nbsp; What am I doing wrong?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;PS Z:\&amp;gt; Get-TlsCipherSuite | Format-Table -Property CipherSuite, Name, hash&lt;/P&gt;&lt;P&gt;CipherSuite Name Hash&lt;BR /&gt;----------- ---- ----&lt;BR /&gt;0 TLS_AES_256_GCM_SHA384&lt;BR /&gt;0 TLS_AES_128_GCM_SHA256&lt;BR /&gt;49200 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384&lt;BR /&gt;49199 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256&lt;BR /&gt;49192 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 SHA384&lt;BR /&gt;49191 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 SHA256&lt;BR /&gt;49172 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA SHA1&lt;BR /&gt;49171 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA SHA1&lt;BR /&gt;0 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384&lt;BR /&gt;49195 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256&lt;BR /&gt;49188 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 SHA384&lt;BR /&gt;49187 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 SHA256&lt;BR /&gt;49162 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA SHA1&lt;BR /&gt;49161 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA SHA1&lt;BR /&gt;157 TLS_RSA_WITH_AES_256_GCM_SHA384&lt;BR /&gt;156 TLS_RSA_WITH_AES_128_GCM_SHA256&lt;BR /&gt;61 TLS_RSA_WITH_AES_256_CBC_SHA256 SHA256&lt;BR /&gt;60 TLS_RSA_WITH_AES_128_CBC_SHA256 SHA256&lt;BR /&gt;53 TLS_RSA_WITH_AES_256_CBC_SHA SHA1&lt;BR /&gt;47 TLS_RSA_WITH_AES_128_CBC_SHA SHA1&lt;BR /&gt;0 TLS_CHACHA20_POLY1305_SHA256&lt;BR /&gt;0 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 17:57:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7200853#M62690</guid>
      <dc:creator>Ted Wood</dc:creator>
      <dc:date>2023-11-15T17:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201070#M62691</link>
      <description>&lt;P dir="auto" style="margin: 0;"&gt;&lt;BR /&gt;Greetings!&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;Please check if this is happening across different browsers.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 08:17:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201070#M62691</guid>
      <dc:creator>BPSingh</dc:creator>
      <dc:date>2023-11-20T08:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201282#M62693</link>
      <description>&lt;P&gt;Yes, this happens with both Chrome and Edge browsers.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 19:23:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201282#M62693</guid>
      <dc:creator>Ted Wood</dc:creator>
      <dc:date>2023-11-21T19:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201299#M62694</link>
      <description>&lt;P dir="auto" style="margin: 0;"&gt;Greetings!&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;This needs to be investigated. Please logs a support case for further investigation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 05:41:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201299#M62694</guid>
      <dc:creator>BPSingh</dc:creator>
      <dc:date>2023-11-22T05:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201330#M62695</link>
      <description>&lt;P&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1944977"&gt;@BPSingh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Well, I seem to have messed up badly.&amp;nbsp; I added a cipher to the CIPHERS-USER parameter in SecuritySettings.prop and successfully ran mxcipher -e 2.&amp;nbsp; After I restarted the HP SIM service with mxstop/mxstart I could no longer connect to HP SIM from a browser, nor would HP SIM recognize mxcipher commands.&amp;nbsp; I tried to recover using my backup copy of&amp;nbsp;SecuritySettings.prop but I get this message:&lt;/P&gt;
&lt;P&gt;C:\Program Files\HP\Systems Insight Manager&amp;gt;mxcipher -e 1&lt;BR /&gt;There was a problem connecting to the HPE Systems Insight Manager server. Make sure that:&lt;BR /&gt;1. Your username has been added to HPE Systems Insight Manager.&lt;BR /&gt;2. Your username and password, if specified, are correctly spelled.&lt;BR /&gt;3. HPE Systems Insight Manager is running.&lt;BR /&gt;4. You used '--' for any long options and double quotes if your username includes a domain.&lt;BR /&gt;Example: &amp;lt;commandname&amp;gt; --user "mydomain\myusername" --pass mypassword&lt;/P&gt;
&lt;P&gt;As far as I can tell, there was a typo in the cipher name that I added to the&amp;nbsp;CIPHERS-USER parameter in SecuritySettings.prop but why would that cause HP SIM to go unresponsive?&amp;nbsp; Is there any way to recover from this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 05:46:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201330#M62695</guid>
      <dc:creator>Ted Wood</dc:creator>
      <dc:date>2023-11-24T05:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201493#M62696</link>
      <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;This can also happen if the SIM database has been corrupted but you have already attempted to restore from backup but get the error that you mentioned.&lt;/P&gt;&lt;P&gt;Could you check if HP SIM service is up and running? Please restart the service and check.&lt;/P&gt;&lt;P&gt;If SIM version is 7.x, then please check this.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=kc0102390en_us&amp;amp;docLocale=en_US" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=kc0102390en_us&amp;amp;docLocale=en_US&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2023 05:25:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7201493#M62696</guid>
      <dc:creator>BPSingh</dc:creator>
      <dc:date>2023-11-25T05:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7205918#M62697</link>
      <description>&lt;P&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1944977"&gt;@BPSingh&lt;/a&gt;&amp;nbsp;Thanks to everyone that his helped so far.&amp;nbsp; I was able to get the HP SIM installation recovered and to *mostly* use TLS 1.2.&amp;nbsp; However our security team again flagged my HP SIM server as using TLS 1.0 and 1.1.&amp;nbsp; Ports 50000, 50001, 50002 and 50005 are at TLS 1.2 or are not even using TLS but port 50004 is still using TLS 1.0 and 1.1.&lt;/P&gt;
&lt;P&gt;A netstat shows that all of those ports are associated with the process ID of&amp;nbsp;mxdomainmgr.exe.&amp;nbsp; Why would port 50004 be still using TLS 1.0 and 1.1???&lt;/P&gt;
&lt;P&gt;This is starting to drive me a bit mental...&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 05:52:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7205918#M62697</guid>
      <dc:creator>Ted Wood</dc:creator>
      <dc:date>2024-02-02T05:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: HP SIM and TLS1.0/1.1</title>
      <link>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7205957#M62698</link>
      <description>&lt;P&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;The port 50004 is only used for receiving WBEM events. If the vulnerability is reported only on this port, probably the port can be disabled as a workaround.&lt;/P&gt;&lt;P&gt;The file globalsettings.props has the setting WBEM_Indications_Listener_Port=50004, which enables the port.&lt;/P&gt;&lt;P&gt;Set the value to WBEM_Indications_Listener_Port=99999 and restart SIM , during SIM restart it can throw an error like( in mxdomainmgr log) that port is out of range and does not enable the port. This should not impact any other operations of SIM.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 07:51:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hp-sim-and-tls1-0-1-1/m-p/7205957#M62698</guid>
      <dc:creator>BPSingh</dc:creator>
      <dc:date>2024-02-02T07:51:56Z</dc:date>
    </item>
  </channel>
</rss>

