LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-26-2017, 11:51 PM   #1
LittleMaster
Member
 
Registered: Jun 2012
Posts: 121
Blog Entries: 1

Rep: Reputation: Disabled
Reconfigure the service to use a unique Diffie-Hellman moduli of 2048 bits or greater.


Hi All,

I have scanned my server with Symantec network scan and I've got below alert message

I've made google search but unable to point out to exact solutions to fix the vulnerability

Any help regarding this vulnerability will be very helpful

Thanks in advance


Solutions:
Reconfigure the service to use a unique Diffie-Hellman moduli of 2048 bits or greater.

Vulnerable connection combinations :

SSL/TLS version : TLSv1.1
Cipher suite : TLS1_CK_DHE_RSA_WITH_AES_128_CBC_SHA
Diffie-Hellman MODP size (bits) : 1024
Warning - This is a known static Oakley Group2 modulus. This may make
the remote host more vulnerable to the Logjam attack.
Logjam attack difficulty : Hard (would require nation-state resources)

SSL/TLS version : TLSv1.0
Cipher suite : TLS1_CK_DHE_RSA_WITH_AES_128_CBC_SHA
Diffie-Hellman MODP size (bits) : 1024
Warning - This is a known static Oakley Group2 modulus. This may make
the remote host more vulnerable to the Logjam attack.
Logjam attack difficulty : Hard (would require nation-state resources)

Reconfigure the service to use a unique Diffie-Hellman moduli of 2048 bits or greater.
 
Old 12-27-2017, 09:39 AM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Hi,

You didn't say what service you're scanning against the logjam vulnerability, but you should also ditch TLSv1.0 and TLSv1.1 and use only TLSv1.2

As for your question, take a look here


Regards
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Strengthening Diffie-Hellman in SSH and TLS LXer Syndicated Linux News 0 10-29-2015 05:50 PM
How to check Diffie-Hellman Ciphers and DHE_EXPORT for tomcat gaurav_s Linux - Networking 0 06-26-2015 02:45 PM
Can Diffie Hellman and Digital Signature Algorithm be simulated using NS2? CharanyaJ Linux - Newbie 2 02-14-2012 08:49 AM
SSH server not responding to Diffie-Hellman Key Exchange request message (34) x_gaurav Programming 0 03-16-2009 09:27 AM
2048 bits for openssh and openssl powah Linux - Software 0 04-17-2008 03:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration