Archived copy of an article by Omer Sen, originally published on LinkedIn on 2018-04-02.
Original: https://www.linkedin.com/pulse/rsa-enough-rapid7-insightvmnexpose-console-omer-sen/ · ← back to faruk.net
Original: https://www.linkedin.com/pulse/rsa-enough-rapid7-insightvmnexpose-console-omer-sen/ · ← back to faruk.net
If RSA is not enough for Rapid7 InsightVM/Nexpose Console
@Rapid7 Vulnerability Manager products (InsightVM or Nexpose) comes with great power and security but sometimes it may be a requirement to use a better encryption algorithm on Web User Interface (or Web Interface) aka the application that is opened when you connect to 3780.
If you want to change generated keys with RSA algorithm and you want to use Elliptic Curve (ECC) Keys you simply need to follow this steps
- Be sure you have 6.5.10 version of Nexpose/InsightVM. Normally product updates itself to latest version if it has connection to internet. For release notes of product you can visit https://help.rapid7.com/nexpose/en-us/release-notes/
- Login to Nexpose/InsightVM Console with SSH with nexpose user and become root
- # mkdir /root/ECC
- Backup nscweb.ks file if there is any with command "cp -f /opt/rapid7/nexpose/nsc/keystores/nscweb.ks /root/ECC/nscweb.ks.ORG" as root
- # /opt/rapid7/nexpose/_jvm1.8.0_162/bin/keytool -genkey -alias nscweb -keyalg EC -keystore /root/ECC/nscweb.ks -keysize 256 -keypass 'r@p1d7k3y$t0r3' -storepass 'r@p1d7k3y$t0r3' -dname "CN=ivm.example.com OU=EMEA, O=Example Ltd, L=London, C=GB" -validity 3650
- Copy created nscweb.ks to /opt/rapid7/nexpose/nsc/keystores/ with "cp -f /root/ECC/nscweb.ks /opt/rapid7/nexpose/nsc/keystores/nscweb.ks"
- Restart console with "systemctl restart nexposeconsole"
After that you can see certificate algorithm is "ANSI X9.62 elliptic curve prime256v1 (aka secp256r1, NIST P-256)"
For further reading is at Documentation page https://help.rapid7.com and https://nexpose.help.rapid7.com/docs/managing-the-security-console