Articles in this section

CVE-2015-4000 LOGJAM TLS DH vulnerability on Plesk server

Plesk for Windows Plesk for Linux kb: technical ABT: Group B

Applicable to:

  • Plesk for Linux
  • Plesk for Windows

Situation

CVE-2015-4000 LOGJAM TLS DH vulnerability on Plesk server

Impact

The Logjam attack allows a man-in-the-middle attacker to downgrade vulnerable TLS connections to 512-bit export-grade cryptography. This allows the attacker to read and modify any data passed over the connection. 

Call to Action

Click on a section to expand

Plesk for Linux
  1. Connect to server over SSH.
  2. Run the following command to increase Diffie-Hellman key size to 4096 bit:

    # plesk sbin sslmng -vvv --strong-dh --dhparams-size=4096

    Note: To change the setting for a particular service, option --services=service_name should be used.

Plesk for Windows
    1. Connect to server over RDP.
    2. Open the Group Policy Object Editor: type gpedit.msc in the Start > Run dialogue window:
      gp1.PNG

    3. Expand Computer Configuration > Administrative Templates > Network > SSL Configuration Settings and open the SSL Cipher Suite Order setting:gp2.PNG

    4. Set up a strong cipher suite order. See this list of Microsoft's supported ciphers and Mozilla's TLS configuration instructions:
      gp3.PNG
Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.