certificate for OEM
Our company required all servers to pass the Qualys scan as part of the security requirements.
From Qualys scan, the database servers that have OEM Agent installed are found to be vulnerable for security attack. We're using Oracle provided certificate. Qualys report indicate that Port 3872 (that's used by Agent) in the database servers are vulnerable for :
1. Birthday attacks against TLS ciphers with 64bit block size vulnerability (Sweet32)
Solution:Disable and stop using DES, 3DES, IDEA or RC2 ciphers.
2. SSL Certificate - Invalid Maximum Validity Date Detected
Solution:Please install a server certificate with recommended maximum validity
3.SSL Certificate - Self-Signed Certificate