Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Disabling TLS

This thread has been viewed 58 times
  • 1.  Disabling TLS

    Posted Feb 20, 2018 03:04 AM

    Hi Guys, just want to ask if in CPPM 6.6.7, can disable TLS 1.0 and TLS 1.1 support? I can only see to disable TLS 1.0 but how about TLS 1.1.

    Thanks



  • 2.  RE: Disabling TLS
    Best Answer

    EMPLOYEE
    Posted Feb 20, 2018 03:23 AM

    Cluster wide parameters 

     

     

    Screen Shot 2018-02-20 at 2.20.21 AM.png

     



  • 3.  RE: Disabling TLS

    EMPLOYEE
    Posted Feb 20, 2018 03:24 AM

    This is a screen shot of 6.7.1 but release notes says it was introduced in 6.6.3

    l A new cluster-wide parameter lets you enable or disable TLS v1.1. To use this feature, go to the Administration > Server Manager > Server Configuration > 



  • 4.  RE: Disabling TLS

    Posted Feb 20, 2018 03:45 AM

    Hi tarnold, in my version 6.6.7 I only see Disable TLS 1.0. Do I need to upgrade?



  • 5.  RE: Disabling TLS

    EMPLOYEE
    Posted Feb 20, 2018 03:52 AM

    No, I just check a 6.6.7 and it is listed. Screen Shot 2018-02-20 at 2.50.04 AM.png



  • 6.  RE: Disabling TLS

    Posted Feb 20, 2018 04:04 AM

    sorry, I saw it now. I overlooked it. thanks



  • 7.  RE: Disabling TLS

    EMPLOYEE
    Posted Feb 20, 2018 07:14 AM
    It is not recommended to disable 1.1.


  • 8.  RE: Disabling TLS

    Posted Feb 06, 2020 02:28 PM

    Even disabling TLS 1.0 in cluster wide parameters (ALL) can have wide impact in unmanaged mac environment (college student owned), as I have found out today. Older Macs and Windows 8 could not connect to 802.1x peap even with re-adding the network. It broke on 10.12.6 and didn't break on 10.14. Not sure about in between those versions. As soon as I rolled back the setting on clearpass, most clients reconnected automatically. Some clients needed to forget network and re-add after I reverted the clearpass setting.

    Looks like I'll be updating the stated minimum requirements documentation for new student macs and hope to make the change in the summer.



  • 9.  RE: Disabling TLS

    Posted May 29, 2019 01:31 PM

    We are running 6.5.4.3 on a 7210 controller.  I can not find anywhere to allow or disallow TLS 1.0.  I want to disable TLS 1.0 and enable TLS 1.1 and up but I am not finding it anywhere in the GUI.  Should I be considering doing a firmware upgrade to get those commands?