<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SnapCreator 4.3 how to disable SSL Medium Strength Cipher in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/SnapCreator-4-3-how-to-disable-SSL-Medium-Strength-Cipher/m-p/126457#M27304</link>
    <description>&lt;P&gt;Security scan, ran on server where SCagent is running, found this vulnerability:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;***********************&lt;/P&gt;&lt;P&gt;Synopsis&lt;BR /&gt;The remote service supports the use of medium strength SSL ciphers.&lt;BR /&gt;&lt;BR /&gt;Description&lt;BR /&gt;The remote host supports the use of SSL ciphers that offer medium strength encryption, which we currently regard as those with key lengths at least 56 bits and less than 112 bits.&lt;BR /&gt;&lt;BR /&gt;Note: This is considerably easier to exploit if the attacker is on the same physical network.&lt;BR /&gt;&lt;BR /&gt;Solution&lt;BR /&gt;Reconfigure the affected application if possible to avoid use of medium strength ciphers.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Plugin Output&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Here is the list of medium strength SSL ciphers supported by the remote server :&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Medium Strength Ciphers (&amp;gt; 64-bit and &amp;lt; 112-bit key)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLSv1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; EDH-RSA-DES-CBC3-SHA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kx=DH&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Au=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enc=3DES-CBC(168)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac=SHA1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ECDHE-RSA-DES-CBC3-SHA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kx=ECDH&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Au=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enc=3DES-CBC(168)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac=SHA1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DES-CBC3-SHA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kx=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Au=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enc=3DES-CBC(168)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac=SHA1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;***************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where and how can I disable SSL Medium Strength Cipher? Is it on server where snap creator is running?&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 18:04:11 GMT</pubDate>
    <dc:creator>milan_26</dc:creator>
    <dc:date>2025-06-04T18:04:11Z</dc:date>
    <item>
      <title>SnapCreator 4.3 how to disable SSL Medium Strength Cipher</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SnapCreator-4-3-how-to-disable-SSL-Medium-Strength-Cipher/m-p/126457#M27304</link>
      <description>&lt;P&gt;Security scan, ran on server where SCagent is running, found this vulnerability:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;***********************&lt;/P&gt;&lt;P&gt;Synopsis&lt;BR /&gt;The remote service supports the use of medium strength SSL ciphers.&lt;BR /&gt;&lt;BR /&gt;Description&lt;BR /&gt;The remote host supports the use of SSL ciphers that offer medium strength encryption, which we currently regard as those with key lengths at least 56 bits and less than 112 bits.&lt;BR /&gt;&lt;BR /&gt;Note: This is considerably easier to exploit if the attacker is on the same physical network.&lt;BR /&gt;&lt;BR /&gt;Solution&lt;BR /&gt;Reconfigure the affected application if possible to avoid use of medium strength ciphers.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Plugin Output&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Here is the list of medium strength SSL ciphers supported by the remote server :&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Medium Strength Ciphers (&amp;gt; 64-bit and &amp;lt; 112-bit key)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLSv1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; EDH-RSA-DES-CBC3-SHA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kx=DH&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Au=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enc=3DES-CBC(168)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac=SHA1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ECDHE-RSA-DES-CBC3-SHA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kx=ECDH&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Au=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enc=3DES-CBC(168)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac=SHA1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DES-CBC3-SHA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kx=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Au=RSA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enc=3DES-CBC(168)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac=SHA1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;***************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where and how can I disable SSL Medium Strength Cipher? Is it on server where snap creator is running?&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 18:04:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SnapCreator-4-3-how-to-disable-SSL-Medium-Strength-Cipher/m-p/126457#M27304</guid>
      <dc:creator>milan_26</dc:creator>
      <dc:date>2025-06-04T18:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: SnapCreator 4.3 how to disable SSL Medium Strength Cipher</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SnapCreator-4-3-how-to-disable-SSL-Medium-Strength-Cipher/m-p/126499#M27318</link>
      <description>&lt;P&gt;&lt;SPAN&gt;There is no provision to disable medium strength SSL ciphers in Snap Creator 4.3 release, but Snap Creator 4.3.1 has disabled the usage of these&amp;nbsp;ciphers(like DES &amp;amp; 3DES).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, Snap Creator 4.3.1 has disabled TLSv1 protocol by default. To support backward compatibility, user can enable it by setting&amp;nbsp;ENABLE_SECURITY_PROTOCOL_TLS_V1 parameter to Y in snapcreator.properties and agent.properties file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;User can upgrade Snap Creator to 4.3.1 release to avoid this kind of vulnerabilities.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 13:22:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SnapCreator-4-3-how-to-disable-SSL-Medium-Strength-Cipher/m-p/126499#M27318</guid>
      <dc:creator>Naina</dc:creator>
      <dc:date>2016-12-22T13:22:03Z</dc:date>
    </item>
  </channel>
</rss>

