RecoverPoint and RecoverPoint for VMs Vulnerability report: Weak SSL or TLS Key Exchange detected on RPAs during security scan Port TCP 8082 & 8084
Summary: The SSL or TLS server supports key exchanges that are cryptographically weaker than recommended.
Symptoms
Running a vulnerability scanner on RecoverPoint (RP) shows the following messages:
Weak SSL/TLS Key Exchange detected on RPAs during security scan Port TCP 8082 & 8084
Cause
Key exchanges should provide at least 224 bits of security. This translates to a minimum key size of 2048 bits for Diffie-Hellman and RSA key exchanges.
Resolution
Workaround:
The below script is applicable to both RecoverPoint Classic and RecoverPoint for VMs.
Use the below procedure on all RPAs, and reboot them one at a time.
"Connection to server failed."
Log in to the installation menu of the RPA (admin in RecoverPoint for VMs, boxmgmt in RecoverPoint Classic):
[2] Setup
[8] Advanced options
[4] Run script
Paste the following, and press enter:
MzMyYmJjN2I3NDEwMTY2NDk5ODY1MzExNzYzMGQxMWMKdW5saW1pdGVkCm5vdF9yZXN0cmljdGVk
ClRoZSBpZCBvZiB0aGUgc2NyaXB0IGlzOlJQLTM1NjQ4CkNoYW5nZSBESCBrZXlTaXplIHRvIDIw
NDgKQXNzaWYgSGFsCmlmIFtbIGBncmVwIC1jICJESCBrZXlTaXplIDwgMTAyNCIgL3Vzci9rYXNo
eWEvamF2YS9qcmUvbGliL3NlY3VyaXR5L2phdmEuc2VjdXJpdHlgIC1ndCAwIF1dOyB0aGVuCglz
ZWQgLWkgJ3MvREgga2V5U2l6ZSA8IDEwMjQvREgga2V5U2l6ZSA8IDIwNDgvJyAvdXNyL2thc2h5
YS9qYXZhL2pyZS9saWIvc2VjdXJpdHkvamF2YS5zZWN1cml0eQoJc2VydmljZT1gc3lzdGVtY3Rs
IC0tYWxsIHwgZ3JlcCAtaSB0b21jYXQgfCBzZWQgInMvXC5zZXJ2aWNlLiovLyJ8c2VkICJzLy4q
dG9tY2F0L3RvbWNhdC8iYAoJaWYgW1sgJHtzZXJ2aWNlfSA9ICoidG9tY2F0IiogXV07IHRoZW4K
CQlzeXN0ZW1jdGwgcmVzdGFydCAke3NlcnZpY2V9CgllbHNlCgkJcHMgLWVmIHwgZ3JlcCAidG9t
Y2F0LXN0YXJ0IiB8IGdyZXAgLXYgZ3JlcCB8IGF3ayAne3ByaW50ICQyfSd8eGFyZ3Mga2lsbCAt
OQoJZmkKCWVjaG8gIlNjcmlwdCByYW4gc3VjY2Vzc2Z1bGx5IgplbHNlCgllY2hvICJObyBpc3N1
ZXMgZm91bmQuIE5vIENoYW5nZXMgbWFkZSIKZmkK
#
Resolution:
Dell engineering is investigating this issue. A permanent fix is still in progress. Contact the Dell Customer Support Center or your service representative for assistance and reference this solution ID.