Citrix Licensing server vulnerability TLSv1.0/1.1 on CitrixWebServicesforLicensing
book
Article ID: CTX560634
calendar_today
Updated On:
Description
When running Qualis security report, it reports the following error :
The CitrixWebServicesforLicensing TLSv1.0/1.1 vulnerbility on our Citrix Licensing server.
An attacker can exploit cryptographic flaws to conduct man-in-the-middle type attacks or to decryption communications.

Resolution
- To disable them, move TLSv1 and TLSv1.1 beside the "SSProtocol ALL" with a minus symbol in the config file, as shown below:
File - C:\Program Files (x86)\Citrix\Licensing\WebServicesForLicensing\Apache\conf\extra\httpd-ssl.conf

- Restart Citrix Web Services for Licensing service post the change.
Problem Cause
The SSL Config file has the protocols enabled.
Issue/Introduction
TLS 1 and 1.1 vulnerability on License server
Was this article helpful?
thumb_up
Yes
thumb_down
No