Forum Discussion

Prasad4u's avatar
Prasad4u
Icon for Nimbostratus rankNimbostratus
Jan 08, 2021

Disable Weak Ciphers

Team,

 

I have tried disabling the weak ciphers using the Cipher.

 

Cipher Code : ECDHE+SHA256:HIGH:!SSLv3:!RSA:!RC4:!EXP:!LOW:!ADH:!DHE:!DES:!3DES:!TLSv1:!TLSv1_1:TLSv1_2

 

But Still, I can see few weak Ciphers in Ssllabs.com :

 

 

 

Cipher Suites# TLS 1.2 (suites in server-preferred order) 

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 128

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 256

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 256

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)  ECDH secp384r1 (eq. 7680 bits RSA)  FS  WEAK 128

 

  • Hi Prasad4u,

     

    Try to add !AES on you Cipher Code :

    ECDHE+SHA256:HIGH:!SSLv3:!RSA:!RC4:!EXP:!LOW:!ADH:!DHE:!DES:!3DES:!TLSv1:!TLSv1_1:TLSv1_2:!AES

    Regards