Connectrix, San Navigator: TLS or SSL Weak Message Authentication Code Cipher Suites
Summary: This issue is seen when Connectrix San Navigator is scanned for vulnerabilities and weak ciphers are detected. The schema registry uses port 18082.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Instructions
Below is the list of weak ciphers detected in the scan report:
TLS_DHE_RSA_WITH_AES_256_CBC_SHATLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
The nginx_ssl_conf_sr file is identified as related to weak ciphers.
Steps to replace the weak ciphers:
- Stop the SANnav services using stop-sannav.sh script (/storage/SANnav/Portal_2.3.0_bld315/stop-sannav.sh)
- Copy the nginx_ssl_conf_sr file (/storage/SANnav/Portal_2.3.0_bld315/conf/nginx/nginx_ssl_conf_sr) into outside of the SANnav home and keep as a backup.
- Remove the indicated ciphers below from the nginx_ssl_conf_sr file (/storage/SANnav/Portal_2.3.0_bld315/conf/nginx/nginx_ssl_conf_sr) and save the file.
ssl_ciphers 'TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256:EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:!DSS';
- Start the SANnav services using start-sannav.sh script. (/storage/SANnav/Portal_2.3.0_bld315/start-sannav.sh)
- Wait for 15-20 minutes to make services up.
- Run the scanner again and check whether any weak ciphers are still reported.
- If reported, collect supportsave logs and SAN navigator logs, and engage Broadcom for further investigations.
NOTE: If you encounter any issues with Telemetry registration after performing the above steps, revert the changes in the nginx_ssl_conf_sr file and replace the original "nginx_ssl_conf_sr" file which was backed up in step 2 in the " /storage/SANnav/Portal_2.3.0_bld315/conf/nginx/" location and restart the SANnav services using the script and verify if the telemetry registration is working as expected.
Affected Products
Connectrix SANnavArticle Properties
Article Number: 000218388
Article Type: How To
Last Modified: 03 Jun 2025
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.