Preview Tool

Cisco Bug: CSCup70470 - CPQ listener should never negotiate anonymous ciphers

Last Modified

Jun 18, 2018

Products (1)

  • Cisco Content Security Management Appliance

Known Affected Releases


Description (partial)

After configuring the Centralized Policy, Virus and Outbreak Quarantines feature on your ESA, you may find that connections to the SMA on port 7025 are failing.  Errors such as the following may appear in the logs:

Mon Jul  2 12:00:00 2014 Info: New SMTP DCID 12345 interface address port 7025
Mon Jul  2 12:00:00 2014 Info: DCID 12345 TLS failed: verify error: no certificate from server
Mon Jul  2 12:00:00 2014 Info: DCID 12345 TLS was required but could not be successfully negotiated

This issue occurs when the ESA is offering anonymous ciphers for outbound SMTP connections.  If the SMA accepts such a cipher, the TLS verification process needed for PVO communication will fail.
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.