Sweet32 Mitigation

CVE-2016-2183 (Sweet32)on ASA.


For 9.3(2) and higher:

# conf t
(config)# ssl cipher tlsv1 fips
(config)# ssl cipher tlsv1.1 fips
(config)# ssl cipher tlsv1.2 fips
(config)# exit

Prior to 9.3(2):

# conf t
(config)# ssl encryption aes128-sha1 aes256-sha1 dhe-aes256-sha1 dhe-aes128-sha1
(config)# exit


Amusingly, this leaves some of the the even less-well-protected DES ciphers enabled.

