Unsolved
This post is more than 5 years old
3 Posts
0
21416
August 9th, 2016 16:00
Disabling TLSv1.0 on iDRAC 6, 7, 8 web interface
I am attempting to limit the iDRAC web interface traffic to use only TLSv1.2 per both internal security and PCI security requirements. I have searched and searched for a method to restrict web traffic to this protocol, but without success.
I have upgraded the iDRAC software (and rebooted) to iDRAC 6 2.85 and iDRAC7/8 2.30.30.30, but still find TLSv1.0 still enabled.
Additionally, I have tried to up the SSL ciphers option in the iDRAC configuration area to the highest permitted cipher levels in hopes that this might trigger higher SSL protocol usage in web interface. This was not successful.
Is there a configuration file or setting I can change in either via the web interface or RACADM command to disable TLSv1.0 and keep TLSv1.2 enabled?
Or will there be another patch/upgrade of iDRAC 6/7/8 that I can apply to do the same?
Thank you for your feedback!


sushmab
13 Posts
0
August 10th, 2016 01:00
Hi Bruce,
The feature you are expecting is going to be part of 2.40.40.40 release which will be out by next quarter from Dell. With that version of firmware, users can set, TLS 1.1 or 1.2 as part of iDRAC configuration.
Regards.
Sushma
Bruce-VZ
3 Posts
0
September 21st, 2016 21:00
Sorry for the late response, but this only addresses the iDRAC7 & iDRAC8 systems. Do we have a better ETA on the delivery of 2.40.40.40?
What about iDRAC6 systems? Are they going to be supporting the disabling of TLSv1.0?
VinayaShankarKi
1 Message
0
September 29th, 2016 06:00
Hi Dell Team,
Please update how to disable TLS 1.0/1.1 in dell iDRAC6 ver 2.85 and keep only TLS1.2?
Its required urgently. Please update with the steps to disable TLS1.0
Shawn Corkery
2 Posts
0
October 7th, 2016 10:00
Hi Sushma,
Can you give a more precise ETA for the next update to iDrac6/7/8, that will allow the disabling of TLSv1.0/1.1? Other than next quarter?
Shawn
bobby.l.johnson
1 Message
0
December 6th, 2018 11:00
Hi,
Has there been an update on this issue? I have iDRAC 6 v2.85 and still do not see the option to disable TLSv1.0.
Thanks,
Bobby
AnnaA
1 Message
0
December 7th, 2018 12:00
Hi all,
I have Dell R815/iDRAC6 and with firmware 2.90 both tls 1.1 and 1.2 are enabled – no way to change it to 1.2 only.
With firmware 2.91 the tls 1.1 goes away and I only see tls 1.2 enabled but I also see week cipher that I need to remove – any ideas on some custom cipher string that would disable the 3DES_EDE_CBC_SHA cipher?
Thanks,
subramanien.r
1 Message
0
May 24th, 2021 11:00
looking for RACADM command to disable TLS 1.0 on R710 iDRAC6
DELL-Charles R
Moderator
•
4.7K Posts
•
25.5K Points
0
May 24th, 2021 12:00
Hello subramanien.r,
Version 2.90 introduced Capability to disable TLS1.0 through CLI:
Use racadm command
racadm tlsencryptionstrength get/set
For usage of the command ,try racadm help TlsEncryptionStrength
I'd recommend update to latest Dell iDRAC Monolithic Release 2.92
https://dell.to/3hKPuMG
The racadm command would be the same.
AKUK
1 Rookie
•
11 Posts
0
March 9th, 2023 03:00
This now seems to be possible, sign into iDRAC 8, expand iDRAC Settings, Network, Services, TLS Protocol dropdown now contains "TLS 1.2 Only".