Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  How to disable weak ssl cipher on management interface

    Posted 03-30-2021 11:13
    Hi,

    How to disable weak ssl cipher on Imperva Gateway version 14.0 when PCI compliance required. I try change status from "true" to "false" at bootstrap.xml following a user guide (https://docs.imperva.com/howto/3df18e7e) but ssl cipher doesn't change. and if enable only ECDHE cipher, Gateway not running.
    #On-PremisesWAF(formerlySecuresphere)

    ------------------------------
    Trans Systems
    support
    Huaykwang
    ------------------------------


  • 2.  RE: How to disable weak ssl cipher on management interface

    Posted 04-06-2021 06:24
    Hi ,
    If I got it correctly, from 13.3 (i think) you can do it via gui directly : Global Object > SSL Settings

    Regards

    ------------------------------
    Zuliani
    ------------------------------



  • 3.  RE: How to disable weak ssl cipher on management interface

    Posted 14 days ago

    Hi,

    I am trying to configure this on version 14.7, however i cannot find the SSL Settings page underneath Global Objects how can i get to this page please

    Regards,

    Joy



    ------------------------------
    Joy Ampitan
    Security Engineer
    Ethnos Cyber Limited
    Lagos
    ------------------------------



  • 4.  RE: How to disable weak ssl cipher on management interface

    Posted 14 days ago

    Hi Joy,

    Which SSL settings do you want to configure?

    You can configure SSL settings on GUI if you want to change SSL parameters of protected web servers -> Enabling Disabling SSL ciphers for GW-client negotiation in KRP and TRP mode [e7b24890]

    On the other hand, if you want to change SSL parameters of gateway <-> MX communication, you should follow this guide Inter-component Cipher Suites [3df18e7e]



    ------------------------------
    Cezmi Cal
    Consultant
    Barikat Internet Guvenligi Bilisim Ticaret A.S.
    Ankara
    ------------------------------



  • 5.  RE: How to disable weak ssl cipher on management interface

    Posted 14 days ago

    Hi Cezmi,

    Thank you for your response.

    Unfortunately, I'm unable to access the links you provided - I keep getting the following error:

    ERROR 403 – Permission Required
    You don't have sufficient privileges to view this page. To see the page, try logging in.

    Could you please confirm what level of access my account needs in order to view those pages?

    For further context, I'm trying to change the SSL cipher keys for specific gateways on the MX, as well as specific ports attached to those gateways.

    Looking forward to your guidance.

    Best regards,



    ------------------------------
    Joy Ampitan
    Security Engineer
    Ethnos Cyber Limited
    Lagos
    ------------------------------