cancel
Showing results for 
Search instead for 
Did you mean: 

SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

Hi,

I refer our internal audit review of our McAfee Web Gateway 7.3.2.3 its showing  that our SSL client cipher list ALL:!ADH:+RC4:@STRENGTH is weak and need to change this cipher list

so kindly suggest us on this matter or either we need to upgrade 7.3.2.3 to 7.4.0

Regards,

Mitul Shah

7 Replies
Highlighted
Reliable Contributor exbrit
Reliable Contributor
Report Inappropriate Content
Message 2 of 8

Re: SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

Moved to Web Gateway for better attention.

Reliable Contributor asabban
Reliable Contributor
Report Inappropriate Content
Message 3 of 8

Re: SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

Hi,

those are the defaults on my 7.4 installation, maybe it is suitable to just adopt those settings:

2014-03-14 12_41_54-Edit Settings.png

Best,

Andre

McAfee Employee jscholte
McAfee Employee
Report Inappropriate Content
Message 4 of 8

Re: SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

Hi Mitul,

I'm assuming you ran a vulnerability scan against the MWG's forward proxy port (e.g. 9090) correct? If so, then this can likley be ignored.

Here is the reason.

MWG is the device that clients connect to, to get to the internet (as a forward proxy). They establish the handshake with the MWG (inside your network). The MWG will then establish it's own handshake to the outside world with the server.

In that scenario, it shouldnt really matter what type of handshake is used between the client and the MWG because this happens in side the network. As a result, MWG will offer a lot of cipher suites in order to be compatible with a large number of client types (old or new).

What matters is the handshake between the MWG and the outside world. In that handshake MWG will use the most secure method available to protect the communication.

In effect the client and the MWG could have a very old and unsecure handshake, but the MWG to the server could have the highest possible cipher method and TLS version supported.

If you are using MWG as a reverse proxy then this story changes, because the client would be in the outside world.

Best,

Jon

Re: SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

Hi jon,

I understand your answer and i have one normal query

which handshake method to use the outside the network. ( public network ) and inside the network

Regards,

Mitul Shah

McAfee Employee jscholte
McAfee Employee
Report Inappropriate Content
Message 6 of 8

Re: SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

Hi Mitul,

I don't quite understand the question. How are you using MWG, as a forward or reverse proxy?

Best,

Jon

Re: SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

Hi Jon,

On first communication you mention that '' handshake MWG will use the most secure method available to protect the communication." so i just wanted to know which encryption methods thay use for handshaking for strong secure commnucation.

Regards,

Mitul Shah

Unblack
Level 10
Report Inappropriate Content
Message 8 of 8

Re: SSL weak encryption on mcafee web gateway 7.3.2 ( ALL:!ADH:+RC4:@STRENGTH )

We use: "RC4-SHA:HIGH:!ADH"

If you want to change it, use the openssl syntax.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community