Submit a ticketCall us

Training ClassThe Orion® Platform Instructor-led Classes

Provided by SolarWinds® Academy, these trainings will introduce users to the Orion Platform and its features, management, and navigation. These courses are suitable for users looking to discover new tips, tricks, and ways to adapt their Orion products to better suit their monitoring needs:
Deploying the Orion Platform
Configuring Orion views, maps, and accounts
Configuring Orion alerts and reports

Reserve your seat.

Home > Success Center > Virtualization Manager (VMAN) > VMAN - Knowledgebase Articles > Disable SSLv3 on VMAN

Disable SSLv3 on VMAN

Table of contents
Created by Roger Lofamia, last modified by Chris.Moyer_ret on Dec 13, 2017

Views: 999 Votes: 0 Revisions: 7

Updated: December 13, 2017 

Overview

This article provides steps on how to disable SSLv3 on the VMAN website. Use this procedure in order to reduce the number of devices in your environment that uses SSLv3 and would like to disable SSLv3 on VMAN.

Environment

  • VMAN 6.3.1
  • VMAN 6.3.0

Steps

Tomcat (VMan UI):

Note: Virtual Appliance uses Tomcat and lighttpd

  1. Edit the /usr/share/tomcat/conf/server.xml file nd find the line which reads sslProtocol="TLS".
  2. Insert the following string to a new line underneath:
    sslEnabledProtocols="TLSv1, TLSv1.1, TLSv1.2"
  3. Save the file.
     

lighttpd (VMan Management Console):

Note: It is not possible to turn off the SSLv3 support for this version of lighttpd. It is possible to disable the vulnerable CBC mode of SSLv3 though:

  1. Open the /opt/vmware/etc/lighttpd/lighttpd.conf file.
  2. Replace the cipher list at the end of the file with the following list:
    ssl.cipher-list = "TLSv1+HIGH:!SSLv2:RC4+MEDIUM:!KRB5-DES-CBC3-MD5:!KRB5-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!EDH-DSS-DES-CBC3-SHA:!DES-CBC3-SHA:!AES128-SHA:!AES256-SHA:!aNULL:!eNULL"
  3. Save the file.
Last modified

Tags

Classifications

Public