<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster Active Gate exclude cipher suits in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204003#M24435</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/47783"&gt;@Mizső&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for sharing the update &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Babar&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2023 18:36:53 GMT</pubDate>
    <dc:creator>Babar_Qayyum</dc:creator>
    <dc:date>2023-02-02T18:36:53Z</dc:date>
    <item>
      <title>Cluster Active Gate exclude cipher suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203716#M24381</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;At one of our customers we should exclude some cipher suites from the Cluster Active Gate (with public internet leg).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have followed the documentation and tried 3 types configuration of exluding 3DES chiper suites without success. We have checked the results with nmap, but nothing has changed after the CAG configuration and restart.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-activegate/configuration/how-to-configure-ciphers-on-activegate" target="_blank" rel="noopener noreferrer"&gt;Cipher configuration for ActiveGate | Dynatrace Docs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We always made a change in the CAG config.properties file. These were the 3 types change method.&lt;/P&gt;
&lt;P&gt;1. [com.compuware.apm.webserver]&lt;/P&gt;
&lt;P&gt;excluded-ciphers = TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA,TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA,TLS_RSA_WITH_3DES_EDE_CBC_SHA,TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA,TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA,TLS_RSA_WITH_3DES_EDE_CBC_SHA,TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA,TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA,TLS_RSA_WITH_3DES_EDE_CBC_SHA&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;2. [com.compuware.apm.webserver]&lt;/P&gt;
&lt;P&gt;excluded-ciphers = TLS_DHE_RSA_WITH_3DES_&lt;/P&gt;
&lt;P&gt;excluded-ciphers = TLS_ECDHE_RSA_WITH_3DES_&lt;/P&gt;
&lt;P&gt;excluded-ciphers = TLS_RSA_WITH_3DES_&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;3. [com.compuware.apm.webserver]&lt;/P&gt;
&lt;P&gt;excluded-ciphers = _3DES_&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The results always were the same after restart of the CAG (we tried stop and start also beside restart option). 3DES chiper suites were still available.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nmap -sV --script ssl-enum-ciphers -p 443 localhost&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting Nmap 6.40 (&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://nmap.org/" target="_blank" rel="noopener noreferrer"&gt;http://nmap.org&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;) at 2023-01-19 10:24 CET&lt;/P&gt;
&lt;P&gt;Nmap scan report for localhost (127.0.0.1)&lt;/P&gt;
&lt;P&gt;Host is up (0.000042s latency).&lt;/P&gt;
&lt;P&gt;rDNS record for 127.0.0.1: localhost.localdomain&lt;/P&gt;
&lt;P&gt;PORT&amp;nbsp;&amp;nbsp;&amp;nbsp; STATE SERVICE&amp;nbsp; VERSION&lt;/P&gt;
&lt;P&gt;443/tcp open&amp;nbsp; ssl/http Apache httpd&lt;/P&gt;
&lt;P&gt;| ssl-enum-ciphers:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp; SSLv3: No supported ciphers found&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp; TLSv1.0:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciphers:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_CAMELLIA_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_CAMELLIA_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; compressors:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NULL&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp; TLSv1.1:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciphers:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_CAMELLIA_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_CAMELLIA_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; compressors:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NULL&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp; TLSv1.2:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciphers:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_128_CBC_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_128_GCM_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_256_CBC_SHA256 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_AES_256_GCM_SHA384 - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_RSA_WITH_CAMELLIA_128_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;TLS_RSA_WITH_CAMELLIA_256_CBC_SHA - strong&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; compressors:&lt;/P&gt;
&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NULL&lt;/P&gt;
&lt;P&gt;|_&amp;nbsp; least strength: strong&lt;/P&gt;
&lt;P&gt;Service detection performed. Please report any incorrect results at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://nmap.org/submit/" target="_blank" rel="noopener noreferrer"&gt;http://nmap.org/submit/&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;Nmap done: 1 IP address (1 host up) scanned in 17.69 seconds&lt;/P&gt;
&lt;P&gt;Does anyone have experience with it?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Mizső&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 08:11:00 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203716#M24381</guid>
      <dc:creator>Mizső</dc:creator>
      <dc:date>2023-02-01T08:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude chiper suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203718#M24382</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/47783"&gt;@Mizső&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I am not mistaken. You will have to change the configuration in the &lt;STRONG&gt;custom.properties&lt;/STRONG&gt; file to e&lt;SPAN&gt;xclude the unwanted ciphers&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Babar&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 13:35:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203718#M24382</guid>
      <dc:creator>Babar_Qayyum</dc:creator>
      <dc:date>2023-01-31T13:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude chiper suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203731#M24391</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/22017"&gt;@Babar_Qayyum&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Above mentioned configuration changes were made in the CAG custom.properies file.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Mizső&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 14:22:17 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203731#M24391</guid>
      <dc:creator>Mizső</dc:creator>
      <dc:date>2023-01-31T14:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude chiper suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203766#M24393</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/47783"&gt;@Mizső&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I pointed out the file after reading "&lt;SPAN&gt;We always made a change in the CAG config.properties file.&amp;nbsp;" the statement.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I remember that I have already excluded weak or unwanted ciphers. I will check tomorrow to share with you the exact method.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Babar&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 17:17:50 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203766#M24393</guid>
      <dc:creator>Babar_Qayyum</dc:creator>
      <dc:date>2023-01-31T17:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude chiper suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203769#M24394</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/22017"&gt;@Babar_Qayyum&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It would be nice.&lt;/P&gt;&lt;P&gt;In my original post I made a typo. So we also made a change is custom.properties file, we followed the documnetation.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Mizső&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 17:57:17 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203769#M24394</guid>
      <dc:creator>Mizső</dc:creator>
      <dc:date>2023-01-31T17:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude chiper suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203793#M24403</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/47783"&gt;@Mizső&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is configured in the&amp;nbsp;&lt;STRONG&gt;custom.properties&lt;/STRONG&gt;. Did you restart the cluster after the configurtion?&lt;/P&gt;&lt;P&gt;[com.compuware.apm.webserver]&lt;BR /&gt;ssl‑protocols = TLSv1.2&lt;BR /&gt;excluded-ciphers = TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Babar&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 07:36:48 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203793#M24403</guid>
      <dc:creator>Babar_Qayyum</dc:creator>
      <dc:date>2023-02-01T07:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude chiper suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203795#M24404</link>
      <description>&lt;P&gt;Hi Babar,&lt;/P&gt;&lt;P&gt;Many thans for your switf response.&lt;/P&gt;&lt;P&gt;There were a restart but only process level not host level.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;systemctl stop dynatracegateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;systemctl start dynatracegateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am going to try to restart the cluster active gate host after the configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mizső&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 07:42:27 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/203795#M24404</guid>
      <dc:creator>Mizső</dc:creator>
      <dc:date>2023-02-01T07:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude cipher suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204001#M24433</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/22017"&gt;@Babar_Qayyum&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It is solved. There was a problem with the affected AG. Somehow the clinet istalled an Apache to this AG host beside the DT components. I did not expect this. There was not hardening on the Apache thats why we saw the 3ds chiper suits with nmap. Finally Apache have been disabled and problem solved...&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for your support.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Mizső&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 18:03:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204001#M24433</guid>
      <dc:creator>Mizső</dc:creator>
      <dc:date>2023-02-02T18:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude cipher suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204003#M24435</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/47783"&gt;@Mizső&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for sharing the update &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Babar&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 18:36:53 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204003#M24435</guid>
      <dc:creator>Babar_Qayyum</dc:creator>
      <dc:date>2023-02-02T18:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude cipher suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204027#M24443</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/47783"&gt;@Mizső&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;For clients with important security needs, the list that &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/3364"&gt;@Julius_Loman&lt;/a&gt; compiled is awesome:&lt;BR /&gt;&lt;A href="https://community.dynatrace.com/t5/Dynatrace-tips/Public-endpoint-for-the-Cluster-ActiveGate/td-p/202652" target="_blank"&gt;https://community.dynatrace.com/t5/Dynatrace-tips/Public-endpoint-for-the-Cluster-ActiveGate/td-p/202652&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 08:43:54 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204027#M24443</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2023-02-03T08:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Active Gate exclude cipher suits</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204029#M24445</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/17213"&gt;@AntonioSousa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thanks very much. The link marked as favourite in my browser.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Mizső&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 08:49:45 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Cluster-Active-Gate-exclude-cipher-suits/m-p/204029#M24445</guid>
      <dc:creator>Mizső</dc:creator>
      <dc:date>2023-02-03T08:49:45Z</dc:date>
    </item>
  </channel>
</rss>

