如何连接到没有现代 SSL 密码的服务器

如何连接到没有现代 SSL 密码的服务器

我最近购买了一个旧的 SonicWall 防火墙/VPN 端点,并希望能够访问它。不幸的是,它不通过 HTTP 连接,而是坚持使用 HTTPS。我尝试过的每个浏览器都不再支持连接到具有这样一组旧密码的系统:

$ nmap --script ssl-enum-ciphers -p 8000 ip.add.re.ss

Starting Nmap 7.31 ( https://nmap.org ) at 2016-12-20 09:21 EST
Nmap scan report for ip.add.re.ss
Host is up (0.0061s latency).
PORT     STATE SERVICE
8000/tcp open  http-alt
| ssl-enum-ciphers:
|   SSLv3:
|     ciphers:
|       TLS_RSA_WITH_RC4_128_MD5 (rsa 2048) - C
|       TLS_RSA_WITH_RC4_128_SHA (rsa 2048) - C
|     compressors:
|       NULL
|     cipher preference: client
|     warnings:
|       Broken cipher RC4 is deprecated by RFC 7465
|       Ciphersuite uses MD5 for message integrity
|       Weak certificate signature: SHA1
|   TLSv1.0:
|     ciphers:
|       TLS_RSA_WITH_RC4_128_MD5 (rsa 2048) - C
|       TLS_RSA_WITH_RC4_128_SHA (rsa 2048) - C
|     compressors:
|       NULL
|     cipher preference: client
|     warnings:
|       Broken cipher RC4 is deprecated by RFC 7465
|       Ciphersuite uses MD5 for message integrity
|       Weak certificate signature: SHA1
|_  least strength: C

Nmap done: 1 IP address (1 host up) scanned in 1.19 seconds

除了找到并安装旧版本的 Firefox 之外,还有什么方法可以让我连接到它吗?

答案1

  1. 打开新的 FireFox 选项卡
  2. 类型:about:config
  3. 接受警告
  4. 在搜索栏中搜索以下值并进行如下更改:
    • 搜索security.tls
    • 改成security.tls.version.min0
    • 改成security.tls.version.fallback-limit0
    • 改成security.tls.unrestricted_rc4_fallbacktrue

https://community.rsa.com/docs/DOC-54813

相关内容