Re: Russia attempts mandating installation of root CA on clients for TLS MITM

2022-03-10 Thread Dario Ciccarone (dciccaro) via NANOG
I think the point Eric was trying to make is that while, indeed, the initial, stated goal might be to be able to issue certificates to replace those expired or expiring, there's just a jump/skip/hop to force installation of this root CA certificate in all browsers, or for Russia to block downloa

Re: Catalyst 4500 listening on TCP 6154 on all interfaces

2018-05-09 Thread Dario Ciccarone
NANOG mailing list subscribers:     Hi there. My name is Dario Ciccarone and I work as an Incident Manager on the Cisco PSIRT. The Cisco Product Security Incident Response Team (PSIRT) is responsible for responding to Cisco product security incidents. The Cisco PSIRT is a dedicated, global team

Re: Possible Sudden Uptick in ASA DOS?

2015-07-08 Thread Dario Ciccarone
NANOG members: Hi there. This is Dario Ciccarone from the Cisco PSIRT - the Product Security Incident Response Team. This is to acknowledge we're aware of this issue, and we're working with all the appropriate parties. Indeed, it seems the culprit is Cisco bug ID CSCul36176 -

About the thread "Cisco Routers Vulnerability"

2015-04-13 Thread Dario Ciccarone
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Rashed, NANOG members: Hi there. My name is Dario Ciccarone and I work as an Incident Manager on the Cisco PSIRT - the Product Security Incident Response Team. We saw your email to the NANOG list, with the subject "Cisco Ro

RE: ip options

2009-10-28 Thread Dario Ciccarone (dciccaro)
Luca: Check http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/s ec_acl_sel_drop_ps6350_TSD_Products_Configuration_Guide_Chapter.html#wp1 043334 Not the whole story, but :) Hope it helps, Dario > -Original Message- > From: Luca Tosol