Re: Debian Jessie repo

<[email protected]>
Newsgroups gmane.linux.hardware.dell.poweredge
Message-ID <E8C984B8D1992049BC2A38D18C2D48CB50FFB764@AUSX10HMPS304.AMER.DELL.COM>
Jean-Daniel,

It's not the SSL certificate that's causing the issue but rather some of the ciphers that the web server supports in /opt/dell/srvadmin/lib64/openmanage/apache-tomcat/conf/server.xml. Removing the weak DHE ciphers addresses the issue in Chrome, but need to verify it doesn't affect overall functionality, and also testing with stronger ECDHE ciphers.

Jose De la Rosa
Linux Engineering
Dell | Enterprise Solutions Group

From: Jean-Daniel TISSOT [mailto:[email protected]]
Sent: Tuesday, December 15, 2015 11:33 AM
To: Ben; linux-poweredge-Lists; De La Rosa, Jose
Subject: Re: [Linux-PowerEdge] Debian Jessie repo

All my browsers reject certificates too weak. How can I install a stronger one.
Could Jose De la Rosa make a docker file with a stronger certificate ?
It will be nice.

Thanks.

Le 15. 12. 15 16:50, Ben a écrit :

On Tue, 15 Dec 2015, [email protected]<mailto:[email protected]> wrote:



The default certificate included with OMSA is a self-signed certificate

with a weaker hashing algorithm. It is a best practice to replace the

default certificate with your own stronger signed certificate.

[...]



Here's an idea: how about Dell change the self-signed certificate to use a

stronger/supported hashing algorithm?  That benefits everyone on all kinds

of levels.



Ben

--
Bien cordialement, Jean-Daniel TISSOT<http://chrono-environnement.univ-fcomte.fr/spip.php?article457>
Administrateur Systèmes et Réseaux
Tel: +33 3 81 666 440 Fax: +33 3 81 666 568

Laboratoire Chrono-environnement<http://chrono-environnement.univ-fcomte.fr/>
16, Route de Gray
25030 BESANÇON Cédex

Plan et Accès<https://mapsengine.google.com/map/viewer?mid=zjsxW4ZzZPLY.kp2qPHUBD45c>

_______________________________________________
Linux-PowerEdge mailing list
[email protected]
https://lists.us.dell.com/mailman/listinfo/linux-poweredge
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.