[Freeipa-users] IPA Web Portal using outdated ciphers, breaking with some clients

Jeff Hallyburton jeff.hallyburton at bloomip.com
Fri Jan 29 19:52:10 UTC 2016


Rob,

Chrome is flagging this, and given the error (I've attached a copy) its
probably due to the cipher suite (possibly specifically that it uses
SHA1).  This article has more details and is consistent with what we're
seeing:

http://security.stackexchange.com/questions/83831/google-chrome-your-connection-to-website-is-encrypted-with-obsolete-cryptograph

We've also seen similar issues come up with other applications during
penetration scans (e.g., Qualys) which is why I've noted it here.

Thanks,

Jeff

Jeff Hallyburton
Strategic Systems Engineer
Bloomip Inc.
Web: http://www.bloomip.com

Engineering Support: support at bloomip.com
Billing Support: billing at bloomip.com
Customer Support Portal:  https://my.bloomip.com <http://my.bloomip.com/>

On Fri, Jan 29, 2016 at 2:36 PM, Rob Crittenden <rcritten at redhat.com> wrote:

> Jeff Hallyburton wrote:
> > Hi,
> >
> > We're also seeing that the free-ipa web-portal is using TLS 1.2 by
> > default, which is being flagged as insecure / obsolete.  This also seems
> > to be causing some clients (some instances of Chrome) to fail logins:
> >
> > [Fri Jan 29 18:34:26.638350 2016] [:error] [pid 6603] SSL Library Error:
> > -12286 No common encryption algorithm(s) with client
> >
> >
> > What do we need to do to update this to TLS 1.3?
>
> TLS 1.2 insecure/obsolete? Flagged by what? Need more info on what the
> handshake looks like and what the server configuration is.
>
> AFAIK 1.3 is still in draft form.
>
> rob
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20160129/0ffc615c/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Chrome SSL Cipher SS.png
Type: image/png
Size: 29939 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20160129/0ffc615c/attachment.png>


More information about the Freeipa-users mailing list