Citrix Licensing server vulnerability TLSv1.0/1.1 on CitrixWebServicesforLicensing

Citrix Licensing server vulnerability TLSv1.0/1.1 on CitrixWebServicesforLicensing

book

Article ID: CTX560634

calendar_today

Updated On:

Description

When running Qualis security report, it reports the following error :

The CitrixWebServicesforLicensing TLSv1.0/1.1 vulnerbility on our Citrix Licensing server.
An attacker can exploit cryptographic flaws to conduct man-in-the-middle type attacks or to decryption communications.

image.png

Resolution

  1. To disable them, move TLSv1 and TLSv1.1 beside the "SSProtocol ALL" with a minus symbol in the config file, as shown below:

 

File - C:\Program Files (x86)\Citrix\Licensing\WebServicesForLicensing\Apache\conf\extra\httpd-ssl.conf

image.png

 

  1. Restart Citrix Web Services for Licensing service post the change.

Problem Cause

The SSL Config file has the protocols enabled.

Issue/Introduction

TLS 1 and 1.1 vulnerability on License server