XtremIO:检测到安全漏洞扫描 TLS SSL 服务器支持使用静态密钥密码

Summary: 如何解决使用描述为“TLS/SSL 服务器支持使用静态密钥密码”的“安全漏洞扫描检测到的漏洞的情况。

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

安全漏洞扫描检测到具有如下描述的漏洞: "TLS/SSL Server Supports The Use of Static Key Ciphers. The server is configured to support ciphers known as static key ciphers. These ciphers do not support "Forward Secrecy." In the new specification for HTTP/2, these ciphers have been blacklisted."

提醒:此脚本仅与 XMS 代码 6.4 或更高版本相关。如果“技术”密码未知,请向 XtremIO 支持部门提出服务请求 (SR),以解决此问题。 

使用 disable_static_ciphers-v3.0.0-s4.0.0.py 附加的脚本,用于禁用下面列出的列入黑名单的密码:

IANA Cipher Suite Name == OpenSSL Cipher Suite Name
TLS_RSA_WITH_AES_128_CBC_SHA == AES128-SHA TLS_RSA_WITH_AES_128_CBC_SHA256 == AES128-SHA256 TLS_RSA_WITH_AES_128_GCM_SHA256 == AES128-GCM-SHA256 TLS_RSA_WITH_AES_256_CBC_SHA == AES256-SHA TLS_RSA_WITH_AES_256_CBC_SHA256 == AES256-SHA256 TLS_RSA_WITH_AES_256_GCM_SHA384 == AES256-GCM-SHA384 TLS_RSA_WITH_CAMELLIA_128_CBC_SHA == CAMELLIA128-SHA TLS_RSA_WITH_CAMELLIA_256_CBC_SHA == CAMELLIA256-SHA TLS_DHE_RSA_WITH_AES_128_CBC_SHA == DHE-RSA-AES128-SHA TLS_DHE_RSA_WITH_AES_256_CBC_SHA == DHE-RSA-AES256-SHA TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA == DHE-RSA-CAMELLIA128-SHA TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA == DHE-RSA-CAMELLIA256-SHA TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA == ECDHE-RSA-AES128-SHA TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA == ECDHE-RSA-AES256-SHA TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 == DHE-RSA-AES128-SHA256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 == DHE-RSA-AES256-SHA256 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 == ECDHE-RSA-AES128-SHA256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 == ECDHE-RSA-AES256-SHA384

IANA 密码套件名称:由互联网号码分配机构 (IANA) 定义并在 RFC 和协议规范中使用的正式名称。

OpenSSL 密码套件名称:OpenSSL 库用于同一密码套件的别名或速记。

Affected Products

XtremIO Family, XtremIO X1, XtremIO X2
Article Properties
Article Number: 000227954
Article Type: How To
Last Modified: 18 Jul 2025
Version:  9
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.