HPE Nimble Storage Solution Specialists
1825720 Members
2978 Online
109686 Solutions
New Discussion

Nimble CS3000 and CS5000 disable TLS v1.0 and v1.1

 
Katie2
Occasional Collector

Nimble CS3000 and CS5000 disable TLS v1.0 and v1.1

Good morning.

We need to disable TLS v1.0 and v1.1 on our Nimble devices. Please could some guidance be provided on how to do this and how to confirm the new settings are in place? Also, will the settings continue to be disabled if the devices are rebooted? Will amending the current settings require any downtime? Thank you.

 

3 REPLIES 3
Nick_Dyer
Honored Contributor

Re: Nimble CS3000 and CS5000 disable TLS v1.0 and v1.1

As part of Nimble's Common Criteria certification, it absolutely is possible to disable TLS v1. This is done via the CLI:

group --info | grep -i tlsv 

This will show if it's enabled/disabled

group --edit --tlsv1_enabled {yes|no}

 This will edit the array group for tls v1.

If you need assistance at any point please contact Nimble Support.

Nick Dyer
twitter: @nick_dyer_
aharvey
Frequent Visitor

Re: Nimble CS3000 and CS5000 disable TLS v1.0 and v1.1

This worked great, on all ports except 5394 (Group leader failover communication). Our scans show this port still enabled for the older TLS versions. Is there a way to mitigate this specific port?

Sunitha_Mod
Honored Contributor

Re: Nimble CS3000 and CS5000 disable TLS v1.0 and v1.1

Hello @aharvey

Thank you for writing to us! Since you have posted in an old topic and there is no response yet, I would recommend you to create a new topic using the create "New Discussion" button, so the experts can check and guide you further.