To fix vulnerabilities on your organization's corporate network, you can enable traffic encryption by using the TLS protocol. You can enable TLS encryption protocols and supported cipher suites on Administration Server. Kaspersky Security Center Linux supports the TLS protocol versions 1.0, 1.1, 1.2, and 1.3. You can select the required encryption protocol and cipher suites.
Kaspersky Security Center Linux uses self-signed certificates. You can also use your own certificates. Kaspersky specialists recommend using certificates issued by trusted certificate authorities.
To configure allowed encryption protocols and cipher suites on Administration Server:
klscflag -fset -pv ".core/.independent" -s Transport -n SrvUseStrictSslSettings -v <value> -t d
Specify the <value> parameter of the SrvUseStrictSslSettings flag:
4
—Only the TLS 1.2 and TLS 1.3 protocols are enabled. Also, cipher suites with TLS_RSA_WITH_AES_256_GCM_SHA384 are enabled (these cipher suites are needed for backward compatibility with the previous versions of Kaspersky Security Center Linux). This is the default value.Cipher suites supported for the TLS 1.2 protocol:
Cipher suites supported for the TLS 1.3 protocol:
5
—Only the TLS 1.2 and TLS 1.3 protocols are enabled. For the TLS 1.2 and TLS 1.3 protocols, the specific cipher suites listed below are supported.Cipher suites supported for the TLS 1.2 protocol:
Cipher suites supported for the TLS 1.3 protocol:
We do not recommend using 0, 1, 2, or 3 as the parameter value of the SrvUseStrictSslSettings flag. These parameter values correspond to insecure TLS protocol versions (TLS 1.0 and TLS 1.1) and insecure cipher suites, and are used only for backward compatibility with earlier Kaspersky Security Center versions.
As a result, traffic encryption by using the TLS protocol is enabled.
You can use the KLTR_TLS12_ENABLED and KLTR_TLS13_ENABLED flags to enable the support of the TLS 1.2 and TLS 1.3 protocols, respectively. These flags are enabled by default.
To enable or disable the support of the TLS 1.2 and TLS 1.3 protocols:
Run the command line, and then change your current directory to the directory with the klscflag utility. The klscflag utility is located in the directory where the Administration Server is installed. The default installation path is /opt/kaspersky/ksc64/sbin.
klscflag -fset -pv ".core/.independent" -s Transport -n KLTR_TLS12_ENABLED -v <value> -t d
klscflag -fset -pv ".core/.independent" -s Transport -n KLTR_TLS13_ENABLED -v <value> -t d
Specify the <value> parameter of the flag:
1
—To enable the support of the TLS protocol.0
—To disable the support of the TLS protocol.