Cisco Bug: CSCup70470 - CPQ listener should never negotiate anonymous ciphers
Jun 18, 2018
- Cisco Content Security Management Appliance
Known Affected Releases
Symptom: After configuring the Centralized Policy, Virus and Outbreak Quarantines feature on your ESA, you may find that connections to the SMA on port 7025 are failing. Errors such as the following may appear in the logs: Mon Jul 2 12:00:00 2014 Info: New SMTP DCID 12345 interface 10.0.0.1 address 192.168.0.1 port 7025 Mon Jul 2 12:00:00 2014 Info: DCID 12345 TLS failed: verify error: no certificate from server Mon Jul 2 12:00:00 2014 Info: DCID 12345 TLS was required but could not be successfully negotiated Conditions: This issue occurs when the ESA is offering anonymous ciphers for outbound SMTP connections. If the SMA accepts such a cipher, the TLS verification process needed for PVO communication will fail.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases