Subscribe

Balance 4.2P1 on Chrome: Server has a weak ephemeral Diffie-Hellman public key

Hello all,

 

We're using Balace 4.2P1 for monitoring our vSphere/NetApp environment. Well, Chrome updated and now we're getting this:

 

Server has a weak ephemeral Diffie-Hellman public key

 

This issue has been detected and fixed in Unified Manager and Performance Manager.  Any ideas on when a suitable patch will be available for Balance?

 

So far we're up to 4.2P4 but none of these updates address the issue.

 

Regards,

Igor

Re: Balance 4.2P1 on Chrome: Server has a weak ephemeral Diffie-Hellman public key

OnCommand Balance has not yet been fixed for that CVE:

https://kb.netapp.com/support/index?page=content&id=9010039

 

Re: Balance 4.2P1 on Chrome: Server has a weak ephemeral Diffie-Hellman public key

Yes I know, I've checkout out the available patches and updates to date (oct 2015, FFR)...

 

I was wondering if NetApp has a remedy in the works - or not?

 

Re: Balance 4.2P1 on Chrome: Server has a weak ephemeral Diffie-Hellman public key

When a fix is posted for a product the KB (Security Advisory) will be updated.  If you subscribe to that KB or the entire Product Security area you will be notificed when updates are published.

 

As far as I am aware, OnCommand Balance has not yet reached End of Support status and therefore will be fixed.