From 6a9a1b4821fe8ccf4fe7e4a56e95a5a6ff635cde Mon Sep 17 00:00:00 2001 From: dishantcr7 <64056848+dishantcr7@users.noreply.github.com> Date: Tue, 21 Dec 2021 14:41:55 +0530 Subject: [PATCH] Dishant disable sslv3 (#15) * Bug 1822129: [OMI Engine] Insecure TLS configuration (SSLv3, Compression) * Setting TLS v1.2 as default minimum --- Unix/etc/omicli.conf | 4 ++-- Unix/etc/omiserver.conf | 3 +++ 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/Unix/etc/omicli.conf b/Unix/etc/omicli.conf index 6bd1801f..8b774f8f 100644 --- a/Unix/etc/omicli.conf +++ b/Unix/etc/omicli.conf @@ -43,7 +43,7 @@ #logfile = miclient.log NoSSLv2=true NoSSLv3=true -NoTLSv1_0=false -NoTLSv1_1=false +NoTLSv1_0=true +NoTLSv1_1=true NoTLSv1_2=false NoSSLCompression=true diff --git a/Unix/etc/omiserver.conf b/Unix/etc/omiserver.conf index 6ebf18fc..86a176c6 100644 --- a/Unix/etc/omiserver.conf +++ b/Unix/etc/omiserver.conf @@ -55,6 +55,9 @@ ## NoSSLv2=true NoSSLv3=true +NoTLSv1_0=true +NoTLSv1_1=true +NoTLSv1_2=false NoSSLCompression=true ##