NetApp - ONTAP TLS protocols and ciphers (security config)
NetApp Solution · Config document · referenced from Encryption and certificates
noteThe command asks for a reboot of every node of the cluster, one at a time. It is not a change to make in passing.
The cluster-wide setting that restricts the management interface to TLS 1.2 and to cipher suites with ephemeral key exchange and AES-GCM or AES-256.
| Item | Value |
|---|---|
| Runs on | cluster shell, advanced privilege level, as admin |
| Scope | whole cluster, interface SSL |
| Applied to | not stated in the notes |
| Before | TLSv1.2, TLSv1.1, TLSv1 with ciphers ALL:!LOW:!aNULL:!EXP:!eNULL, FIPS mode off |
| ONTAP version at the time | 9.3, by the command reference the notes refer to |
The command set
# 1. Advanced privilege level set advanced # 2. Show the current configuration security config show # 3. Allow TLSv1.2 only and set the cipher list. # The command warns that all nodes must be rebooted afterwards, one node # at a time, and asks for confirmation; it was answered with Y. security config modify -interface SSL -supported-protocols TLSv1.2 -supported-ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
The cipher string in OpenSSL terms:
| Element | Meaning |
|---|---|
EECDH+AESGCM | ECDHE key exchange with AES-GCM |
EDH+AESGCM | DHE key exchange with AES-GCM |
AES256+EECDH | ECDHE key exchange with AES-256, including CBC suites |
AES256+EDH | DHE key exchange with AES-256, including CBC suites |
The notes end with the confirmation. The node reboots and a security config show after the change are not recorded.
Checked against ONTAP 9.19.1
| As built | Today |
|---|---|
Default protocols TLSv1.2, TLSv1.1, TLSv1 | Default is TLSv1.3,TLSv1.2. TLSv1 is off by default since ONTAP 9.8, TLSv1.1 since 9.12.1; TLSv1.3 exists from 9.11.1 |
-interface SSL | Deprecated since 9.8 |
-supported-ciphers with an OpenSSL cipher string | Deprecated since 9.8. Ciphers are given with -supported-cipher-suites as a comma-separated list of IANA suite names |
-supported-protocols TLSv1.2 | The parameter remains. All protocols at or above the lowest version specified are enabled |
| Reboot of every node after the change | Not verified for current releases |
On a current release this hardening is the default, and the command as written uses two deprecated parameters. On 9.3 it was the right change.