LINUXOR.SK ... open source notes ...

NetApp - ONTAP TLS protocols and ciphers (security config)

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Encryption and certificates

noteThe command asks for a reboot of every node of the cluster, one at a time. It is not a change to make in passing.

The cluster-wide setting that restricts the management interface to TLS 1.2 and to cipher suites with ephemeral key exchange and AES-GCM or AES-256.

ItemValue
Runs oncluster shell, advanced privilege level, as admin
Scopewhole cluster, interface SSL
Applied tonot stated in the notes
BeforeTLSv1.2, TLSv1.1, TLSv1 with ciphers ALL:!LOW:!aNULL:!EXP:!eNULL, FIPS mode off
ONTAP version at the time9.3, by the command reference the notes refer to

The command set

bash
# 1. Advanced privilege level
set advanced

# 2. Show the current configuration
security config show

# 3. Allow TLSv1.2 only and set the cipher list.
#    The command warns that all nodes must be rebooted afterwards, one node
#    at a time, and asks for confirmation; it was answered with Y.
security config modify -interface SSL -supported-protocols TLSv1.2 -supported-ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH

The cipher string in OpenSSL terms:

ElementMeaning
EECDH+AESGCMECDHE key exchange with AES-GCM
EDH+AESGCMDHE key exchange with AES-GCM
AES256+EECDHECDHE key exchange with AES-256, including CBC suites
AES256+EDHDHE key exchange with AES-256, including CBC suites

The notes end with the confirmation. The node reboots and a security config show after the change are not recorded.

Checked against ONTAP 9.19.1

As builtToday
Default protocols TLSv1.2, TLSv1.1, TLSv1Default is TLSv1.3,TLSv1.2. TLSv1 is off by default since ONTAP 9.8, TLSv1.1 since 9.12.1; TLSv1.3 exists from 9.11.1
-interface SSLDeprecated since 9.8
-supported-ciphers with an OpenSSL cipher stringDeprecated since 9.8. Ciphers are given with -supported-cipher-suites as a comma-separated list of IANA suite names
-supported-protocols TLSv1.2The parameter remains. All protocols at or above the lowest version specified are enabled
Reboot of every node after the changeNot verified for current releases

On a current release this hardening is the default, and the command as written uses two deprecated parameters. On 9.3 it was the right change.

← solutionz