Views:
 
TLS 1.2 can only be enabled by turning on supported ciphers. Instructions below provide information of TLS 1.2 supported ciphers only.
 

Customers who adopted this instruction were advised to test compatibility with browsers and applications in staging environment first.

 
SPS version 3.1 or later is required.
 
  1. Log in to command shell.
  2. Execute the following command:

    vi /etc/lighttpd/lighttpd.conf

  3. Replace "var.ssl-cipher-list" with var.ssl-cipher-list = "TLSv1.2:!eNULL:!aNULL".
  4. Press 'ESC'. Type ":wq!" then press 'Enter' to save the changes and exit vi interface.
  5. Execute the following command:

    service lighttpd restart

After applying the changes, SPS web console and Smart Scan will be limited to use TLS 1.2 only.

Known Issues

After applying this solution on SPS, it may display the following error in the SPS Summary page:

Computer Status

Meanwhile, there are corresponding logs viewable in Logs > Reputation Service Log:

Computer Status

This error does not affect the File Reputation Query function. Trend Micro will release a hot fix to address this UI error.

After applying this solution on SPS, Suspicious Object list synchronization fails and the following error message appears:

Settings