Submit a ticketCall us

Looking to compare latest NPM features with previous versions of NPM?
The NPM new feature summary offers a comparison of new features and improvements offered with this release.

 

 

 

 

Home > Success Center > Virtualization Manager (VMAN) > Protect against POODLE vulnerability on Virtualization Manager

Protect against POODLE vulnerability on Virtualization Manager

Table of contents
Created by Interspire Import, last modified by MindTouch on Jun 23, 2016

Views: 1,075 Votes: 0 Revisions: 11

This article applies to Virtualization Manager. For information about protecting against the Poodle security vulnerability (CVE-2014-3566) on VIM, see the general KB article, KB5998.

To disable SSLv3 for Virtualization Manager, modify the configuration of Tomcat and lighttpd.

Tomcat

To modify the Tomcat configuration of the Virtualization Manager user interface:
  1. Open the /usr/share/tomcat/conf/server.xml file, and then search for the line which reads sslProtocol="TLS".
  2. Insert the following string to a new line underneath:
    sslEnabledProtocols="TLSv1, TLSv1.1, TLSv1.2"
  3. Save the file.

Lighttpd

SSLv3 support cannot be turned off for the currently used version of lighttpd, but you can disable the vulnerable CBC mode of SSLv3.

To modify the lighttpd configuration of the Virtualization Manager management console:

  1. Open the /opt/vmware/etc/lighttpd/lighttpd.conf file.
  2. Replace the cipher list at the end of the file with the following list:
    ssl.cipher-list = "TLSv1+HIGH:!SSLv2:RC4+MEDIUM:!KRB5-DES-CBC3-MD5:!KRB5-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!EDH-DSS-DES-CBC3-SHA:!DES-CBC3-SHA:!AES128-SHA:!AES256-SHA:!aNULL:!eNULL"
  3. Save the file.
Last modified
04:11, 23 Jun 2016

Tags

Classifications

Public