Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSLv2 to TLS 1.2

I was connected via SSL VPN and decided to sniff my traffic to see which encryption protocol was being used. To my dismay I saw that it is SSLv2.

This needs to change to at least TLS 1.1. How can this be done?

I have UTM 9.401-11.



This thread was automatically locked due to age.
Parents Reply Children
  • Ryan, I'd be interested in knowing if adding tls-version-min 1.2 or-highest to both client and server config files would work. If you have a paid subscription, I wouldn't do that though.  If that doesn't work, it could be because the Sophos client is an older version, so you may need to download the new client from OpenVPN.  Let us know!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • From the log file....OpenVPN 2.3.8 and  OpenSSL 1.0.1p. Current OpenVPN version is 2.6 and this version does not appear to allow a custom config file.

    Looking at the man page it does appear that I must change the server config file to force TLS with a matching setting on the client.