Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Postgres TLS Settings

This thread has been viewed 20 times
  • 1.  CPPM Postgres TLS Settings

    Posted Jan 30, 2020 02:05 PM

    Our checkbox enforcers InfoSec folks have determined that we must restrict TLS to v1.2 and I'm unable to find a setting for the postgres listener on 5432/tcp. I've played with the Disable TLS version 1.0/1.1 cluster-wide parameters in my lab (running v6.7.8), but I'm still seeing TLSv1.1 in my scans (sslyze --regular --starttls=postgres <pub>:5432).

     

    Is there a way to manage the TLS settings for postgres?



  • 2.  RE: CPPM Postgres TLS Settings

    Posted Feb 10, 2020 02:06 AM

    ,

     

    I'm not aware of such an option be available to the end user.

    However, I pretty sure TAC can login to the database with admin acces and set the SSL requirements.

     

    Not sure if they will comply to your demand though  

     

    Good luck



  • 3.  RE: CPPM Postgres TLS Settings

    Posted Apr 28, 2021 06:59 PM
    Were you ever able to resolve this?  Infosec is flagging me for the same TLSV1.1 and I'd like to disable it.

    ------------------------------
    C
    ------------------------------



  • 4.  RE: CPPM Postgres TLS Settings

    EMPLOYEE
    Posted May 04, 2021 11:09 AM
    At least in CPPM 6.9.5, I see TLS 1.1 is not allowed. You may consider upgrading, or work with Aruba Support.
     * TLS 1.0 Cipher Suites:
         Attempted to connect using 80 cipher suites; the server rejected all cipher suites.
    
     * TLS 1.1 Cipher Suites:
         Attempted to connect using 80 cipher suites; the server rejected all cipher suites.
    
     * SSL 3.0 Cipher Suites:
         Attempted to connect using 80 cipher suites; the server rejected all cipher suites.​


    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------