To fix vulnerabilities on your organization's corporate network, you can enable traffic encryption by using the TLS protocol. You can enable TLS encryption protocols and supported cipher suites on Administration Server and iOS MDM Server. Kaspersky Security Center supports the TLS protocol versions 1.0, 1.1, and 1.2. You can select the required encryption protocol and cipher suites.
Kaspersky Security Center uses a self-signed certificates. Additional configuration of the iOS devices is not required. You can also use your own certificates. Kaspersky specialists recommend to use certificates issued by trusted certificate authorities.
Administration Server
To configure allowed encryption protocols and cipher suites on the Administration Server:
klscflag -fset -pv ".core/.independent" -s Transport -n SrvUseStrictSslSettings -v <value> -t d
Specify the <value> parameter of the SrvUseStrictSslSettings flag:
4
—only the TLS 1.2 protocol is enabled. Also cipher suites with TLS_RSA_WITH_AES_256_GCM_SHA384 are enabled (this cipher suites are needed for backward compatibility with Kaspersky Security Center 11). This is default value.Cipher suites supported for the TLS 1.2 protocol:
5
—only the TLS 1.2 protocol is enabled. For the TLS 1.2 protocol, the specific cipher suites listed below are supported.Cipher suites supported for the TLS 1.2 protocol:
We do not recommend using 0, 1, 2, or 3 as the parameter value of the SrvUseStrictSslSettings flag. These parameter values correspond to insecure TLS protocol versions (the TLS 1.0 and TLS 1.1 protocols) and insecure cipher suites and are used only for backward compatibility with earlier Kaspersky Security Center versions.
iOS MDM Server
The connection between the iOS devices and the iOS MDM Server is encrypted default.
To configure allowed encryption protocols and cipher suites on the iOS MDM Server:
HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\Components\34\Connectors\KLIOSMDM\1.0.0.0\Conset
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\KasperskyLab\Components\34\Connectors\KLIOSMDM\1.0.0.0\Conset
StrictSslSettings
name.DWORD
as the key type.2
—the TLS 1.0, TLS 1.1, and TLS 1.2 protocols are enabled.3
—only the TLS 1.2 protocol is enabled (default value).