Guest

Preview Tool

Cisco Bug: CSCup70470 - CPQ listener should never negotiate anonymous ciphers

Last Modified

Jun 18, 2018

Products (1)

  • Cisco Content Security Management Appliance

Known Affected Releases

8.1.1-013

Description (partial)

Symptom:
After configuring the Centralized Policy, Virus and Outbreak Quarantines feature on your ESA, you may find that connections to the SMA on port 7025 are failing.  Errors such as the following may appear in the logs:

Mon Jul  2 12:00:00 2014 Info: New SMTP DCID 12345 interface 10.0.0.1 address 192.168.0.1 port 7025
Mon Jul  2 12:00:00 2014 Info: DCID 12345 TLS failed: verify error: no certificate from server
Mon Jul  2 12:00:00 2014 Info: DCID 12345 TLS was required but could not be successfully negotiated

Conditions:
This issue occurs when the ESA is offering anonymous ciphers for outbound SMTP connections.  If the SMA accepts such a cipher, the TLS verification process needed for PVO communication will fail.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.