Werk #15070: Drop support for weak DH ciphers
Component | User interface | ||||||
Title | Drop support for weak DH ciphers | ||||||
Date | Mar 30, 2023 | ||||||
Level | Trivial Change | ||||||
Class | Security Fix | ||||||
Compatibility | Compatible - no manual interaction needed | ||||||
Checkmk versions & editions |
|
With this Werk two TLS ciphers are disabled from the stunnel configuration. stunnel is used when the Encrypt communication option in Enable Livestatus access via network (TCP) or Notification Spooler Configuration is used.
To our knowledge no attacks on these ciphers are known, this is a hardening measure.
We rate this with a CVSS of 0 (None) (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N). This CVSS is primarily meant to please automatic scanners.