disable tls1.0 (open vas)


Securty scan is showing tls1.0 enabled for port 9390 (openvas).

is there a way to disable it form the server entirely?? or does it have to be disabled for each service?? if so, how do i disable it for openvas?

  • tcaetano,

    TLS1.0 is enabled, but not used by openvas manager. Openvas scanner uses TLS1.0 for its scans (as it needs to scan for clients using TLS1.0 on your network.

    In such, this is actually the one case were we do not actually want TLS1.0 disabled.
  • for this case nessus is scanning the alien vault server itself,  is this a false positive then??
