Forum Discussion
Sriram_Shanmuga
Altostratus
Oct 03, 2018How to disable weak cipher from Client SSL Profile
Hi,
We have disabled few ciphers and we have rating "A" in qualys ssl checker portal.
We have a requirement to disable weak ciphers as well.
Could some one advice how to disable weak ciphers.
Pl...
- Oct 03, 2018
By using DEFAULT:@STRENGTH command you can preferred the ciphers to use only Strength.
Mmathew-AMS
Nimbostratus
Feb 17, 2022Hi Dhebal76, did you get to solve this problem. Pls share the Cypher string used
iHugoF
Nimbostratus
Feb 18, 2022This worked for me:
ECDHE:!RSA:ECDHE_ECDSA:!SSLV3:!RC4:!EXP:!DES:!3DES:TLSV1_3:!ECDHE-RSA-AES128-CBC-SHA:!ECDHE-RSA-AES256-CBC-SHA:!ECDHE-RSA-AES256-SHA384:!ECDHE-RSA-AES128-SHA256
- RockBDOct 25, 2022
Altocumulus
Thanks for the full steatment which will help a lot to exclude the Cipher Suites.
My question is if i disable those Cipher Suites that means user can't communicate with that Cipher Suites to my web server. So, isn't that lead to limtating access to the site my disabling those cihper Suites.