enable_deprecated_protocols

The API enables all versions of TLS (including deprecated SSL protocols) on either the current system or on all associated managed units.

After you run the disable_deprecated_protocols API to disable TLS 1.1 and enable TLS 1.2, you might need to re-enable TLS 1.1. This API enables the deprecated protocols (TLS 1.0 and TLS 1.1) and disables TLS 1.2.

This API runs only on a central manager.

This API is available in Guardium V10.1.4 and later.

GuardAPI syntax

enable_deprecated_protocols parameter=value

Parameters

Parameter Value type Description
all Boolean Determines whether to enable deprecated TLS protocols on all associated managed units. Valid values:
  • 0 (false): Enable deprecated TLS protocols on this machine only.
  • 1 (true): Enable deprecated TLS protocols on this machine and associated managed units.

Default = 0 (false)

api_target_host String

Specifies the target hosts where the API executes. Valid values:
  • all_managed: execute on all managed units but not the central manager
  • all: execute on all managed units and the central manager
  • group:<group name>: execute on all managed units identified by <group name>
  • host name or IP address of a managed unit: specified from the central manager to execute on a managed unit.  For example, api_target_host=10.0.1.123.
  • host name or IP address of the central manager: specified from a managed unit to execute on the central manager. For example, api_target_host=10.0.1.123.

IP addresses must conform to the IP mode of your network. For dual IP mode, use the same IP protocol with which the managed unit is registered with the central manager. For example, if the registration uses IPv6, specify an IPv6 address. The hostname is independent of IP mode and can be used with any mode.

Examples

The following command enables the deprecated protocols on managed units:

grdapi enable_deprecated_protocols all=true
Sample output:
Warning this function enables insecured communications protocols.
Delegating to MUs
Deprecated protocols enabled.
ok