Skybox Appliance 8000 Quick Start Guide
Skybox version 10.1.200
26
There are 3 possible configurations for TLS:
›
Default (High) Security configuration for SSL: TLS versions 1.2 and higher are
enabled
Supported browsers are: Firefox 27, Chrome 30, Internet Explorer 11 on
Windows 7, Edge, Opera 17, Safari 9, Android 5.0, Java 8, and higher.
›
Medium Security configuration for SSL: TLS versions 1.1 and higher are
enabled
Supported browsers are: Firefox 1, Chrome 1, Internet Explorer 7, Opera 5,
Safari 1, Windows XP Internet Explorer 8, Android 2.3, Java 7, and higher.
›
Low Security configuration for SSL: All TLS versions are enabled
Supported browsers are: Windows XP Internet Explorer 6, Java 6, and higher.
The configuration settings are stored in
etc/httpd/conf.d/skyboxwebadmin.conf
Important: Use the highest TLS configuration that supports your browser.
To change the TLS configuration settings
1
Make a backup of
skyboxwebadmin.conf
2
Open
skyboxwebadmin.conf
(using
vi
).
3
Comment out the default security configuration by adding “
#
” at the beginning
of the
SSLProtocol
and
SSLCipherSuite
lines.
# Default Security configuration for SSL. Oldest compatible clients:
Firefox 27, Chrome 30, IE 11 on Windows 7, Edge, Opera 17, Safari 9,
Android 5.0, and Java 8.
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-
SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-
ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-
SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-
SHA256
4
Uncomment either
Medium
or
Low
(not both) by deleting “
#
” from the
appropriate
SSLProtocol
and
SSLCipherSuite
lines.
Note: Do not uncomment the title line (
Medium Security
or
Low
Security
).
# Medium Security configuration for SSL. Oldest compatible clients: Firefox
1, Chrome 1, IE 7, Opera 5, Safari 1, Windows XP IE8, Android 2.3, Java 7
#SSLProtocol all -SSLv3
#SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-
POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-
ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-
SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-
AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-
AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-
AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-
SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-
SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-
SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS