Cipher suites supported by TLS1.1. and 1.2IBM Domino 8.5.3 and mitigating the BEAST attack on TLS (SSLTest)None of the cipher suites supported by the client application are supported by the serverHow can I verify if TLS 1.2 is supported on a remote web server from the RHEL/CentOS shell?Windows Server 2008 R2 - SHA2 based Cipher SuitesHow to set “server preference” for tls cipher suites?Exchange 2010 rejecting Amazon SES TLS with UntrusedRootHow to configure IIS 7.5 SSL TLS to work with iOS 9 ATSopenvpn, option tls-cipher not working, no shared cipherCipher suits supported by TLS1.1. and 1.2TLS 1.2 client hello triggers TCP Reset from 2012 R2

Why do galaxies collide?

Capital gains on stocks sold to take initial investment off the table

Why did the soldiers of the North disobey Jon?

Is Big Ben visible from the British museum?

How was the blinking terminal cursor invented?

How to handle professionally if colleagues has referred his relative and asking to take easy while taking interview

bash: Counting characters within multiple files

Omit property variable when using object destructuring

What is the conversion rate for Sorcery Points to Spell Points?

Is Precocious Apprentice enough for Mystic Theurge?

When did Britain learn about American independence?

Can I pay my credit card?

How to know the path of a particular software?

Have there been any examples of re-usable rockets in the past?

Why does the U.S military use mercenaries?

Why is the marginal distribution/marginal probability described as "marginal"?

Gimp perspective tool is not actually transforming

A person lacking money who shows off a lot

What would a Dragon have to exhale to cause rain?

When the match time is called, does the current turn end immediately?

Resistor Selection to retain same brightness in LED PWM circuit

Holding rent money for my friend which amounts to over $10k?

Failing students when it might cause them economic ruin

Is it standard for US-based universities to consider the ethnicity of an applicant during PhD admissions?



Cipher suites supported by TLS1.1. and 1.2


IBM Domino 8.5.3 and mitigating the BEAST attack on TLS (SSLTest)None of the cipher suites supported by the client application are supported by the serverHow can I verify if TLS 1.2 is supported on a remote web server from the RHEL/CentOS shell?Windows Server 2008 R2 - SHA2 based Cipher SuitesHow to set “server preference” for tls cipher suites?Exchange 2010 rejecting Amazon SES TLS with UntrusedRootHow to configure IIS 7.5 SSL TLS to work with iOS 9 ATSopenvpn, option tls-cipher not working, no shared cipherCipher suits supported by TLS1.1. and 1.2TLS 1.2 client hello triggers TCP Reset from 2012 R2






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















We have SSLv3 disabled in DataPower. I ran sslscan to check what all cipher suites can be used currently during SSL handshake.



In the sslscan output, I have found out that below cipher suites are being accepted.



TLSv1 256 bits AES256-SHA
TLSv1 128 bits AES128-SHA
TLSv1 168 bits DES-CBC3-SHA
TLSv1 128 bits RC4-SHA

Preferred Server Cipher: TLSv1 256 bits AES256-SHA


I then, disabled TLS1.0 on DataPower (server) and ran the sslscan again. The result was not what I was expecting.
All the ciphersuites including the ones which were accepted during handshake over TLS1.0 are being rejected.



How would I come to know, which cipher suits my server will accept if I disable TLS1.0?










share|improve this question















migrated from security.stackexchange.com Dec 15 '15 at 14:43


This question came from our site for information security professionals.













  • 2





    This is really a question for serverfault (where you should specify what software you're using). If you want to know what cypher suites you can use with OpenSSL (one of the implementation of TLS), you can go there: openssl.org/docs/manmaster/apps/ciphers.html

    – Stephane
    Dec 15 '15 at 14:00











  • You also might want to check the appropriate RFC.

    – Iszi
    Dec 15 '15 at 14:26

















1















We have SSLv3 disabled in DataPower. I ran sslscan to check what all cipher suites can be used currently during SSL handshake.



In the sslscan output, I have found out that below cipher suites are being accepted.



TLSv1 256 bits AES256-SHA
TLSv1 128 bits AES128-SHA
TLSv1 168 bits DES-CBC3-SHA
TLSv1 128 bits RC4-SHA

Preferred Server Cipher: TLSv1 256 bits AES256-SHA


I then, disabled TLS1.0 on DataPower (server) and ran the sslscan again. The result was not what I was expecting.
All the ciphersuites including the ones which were accepted during handshake over TLS1.0 are being rejected.



How would I come to know, which cipher suits my server will accept if I disable TLS1.0?










share|improve this question















migrated from security.stackexchange.com Dec 15 '15 at 14:43


This question came from our site for information security professionals.













  • 2





    This is really a question for serverfault (where you should specify what software you're using). If you want to know what cypher suites you can use with OpenSSL (one of the implementation of TLS), you can go there: openssl.org/docs/manmaster/apps/ciphers.html

    – Stephane
    Dec 15 '15 at 14:00











  • You also might want to check the appropriate RFC.

    – Iszi
    Dec 15 '15 at 14:26













1












1








1








We have SSLv3 disabled in DataPower. I ran sslscan to check what all cipher suites can be used currently during SSL handshake.



In the sslscan output, I have found out that below cipher suites are being accepted.



TLSv1 256 bits AES256-SHA
TLSv1 128 bits AES128-SHA
TLSv1 168 bits DES-CBC3-SHA
TLSv1 128 bits RC4-SHA

Preferred Server Cipher: TLSv1 256 bits AES256-SHA


I then, disabled TLS1.0 on DataPower (server) and ran the sslscan again. The result was not what I was expecting.
All the ciphersuites including the ones which were accepted during handshake over TLS1.0 are being rejected.



How would I come to know, which cipher suits my server will accept if I disable TLS1.0?










share|improve this question
















We have SSLv3 disabled in DataPower. I ran sslscan to check what all cipher suites can be used currently during SSL handshake.



In the sslscan output, I have found out that below cipher suites are being accepted.



TLSv1 256 bits AES256-SHA
TLSv1 128 bits AES128-SHA
TLSv1 168 bits DES-CBC3-SHA
TLSv1 128 bits RC4-SHA

Preferred Server Cipher: TLSv1 256 bits AES256-SHA


I then, disabled TLS1.0 on DataPower (server) and ran the sslscan again. The result was not what I was expecting.
All the ciphersuites including the ones which were accepted during handshake over TLS1.0 are being rejected.



How would I come to know, which cipher suits my server will accept if I disable TLS1.0?







tls






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Dec 15 '15 at 15:07









D34DM347

1,34521631




1,34521631










asked Dec 15 '15 at 13:55









user2607367user2607367

65




65




migrated from security.stackexchange.com Dec 15 '15 at 14:43


This question came from our site for information security professionals.









migrated from security.stackexchange.com Dec 15 '15 at 14:43


This question came from our site for information security professionals.









  • 2





    This is really a question for serverfault (where you should specify what software you're using). If you want to know what cypher suites you can use with OpenSSL (one of the implementation of TLS), you can go there: openssl.org/docs/manmaster/apps/ciphers.html

    – Stephane
    Dec 15 '15 at 14:00











  • You also might want to check the appropriate RFC.

    – Iszi
    Dec 15 '15 at 14:26












  • 2





    This is really a question for serverfault (where you should specify what software you're using). If you want to know what cypher suites you can use with OpenSSL (one of the implementation of TLS), you can go there: openssl.org/docs/manmaster/apps/ciphers.html

    – Stephane
    Dec 15 '15 at 14:00











  • You also might want to check the appropriate RFC.

    – Iszi
    Dec 15 '15 at 14:26







2




2





This is really a question for serverfault (where you should specify what software you're using). If you want to know what cypher suites you can use with OpenSSL (one of the implementation of TLS), you can go there: openssl.org/docs/manmaster/apps/ciphers.html

– Stephane
Dec 15 '15 at 14:00





This is really a question for serverfault (where you should specify what software you're using). If you want to know what cypher suites you can use with OpenSSL (one of the implementation of TLS), you can go there: openssl.org/docs/manmaster/apps/ciphers.html

– Stephane
Dec 15 '15 at 14:00













You also might want to check the appropriate RFC.

– Iszi
Dec 15 '15 at 14:26





You also might want to check the appropriate RFC.

– Iszi
Dec 15 '15 at 14:26










1 Answer
1






active

oldest

votes


















1














Your output only references TLS 1.0, and disabling it refuses those disabled TLS 1.0 choices as it should. Refer to the DataPower references and documentation to support TLS 1.1 and TLS 1.2 as well as configuring cipher suites. Start with checking your firmware version and properly upgrading to better support the latest TLS configurations.



Here is a reference for DataPower supporting TSL 1.1 and TLS 1.2 by default in firmware version 6. Your current version may not support anything but TLS 1.0, and not allowing yet to configure TLS 1.1, nor TLS 1.2. http://www-01.ibm.com/support/docview.wss?uid=swg21578730 references specific crypto configurations to get granular enough to resolve issues within each TLS version, such as beast.



Once upgraded and configured re-run sslscan, or alternatives if you would like to compare against sslscan such as testssl.sh.






share|improve this answer























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f743166%2fcipher-suites-supported-by-tls1-1-and-1-2%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    1














    Your output only references TLS 1.0, and disabling it refuses those disabled TLS 1.0 choices as it should. Refer to the DataPower references and documentation to support TLS 1.1 and TLS 1.2 as well as configuring cipher suites. Start with checking your firmware version and properly upgrading to better support the latest TLS configurations.



    Here is a reference for DataPower supporting TSL 1.1 and TLS 1.2 by default in firmware version 6. Your current version may not support anything but TLS 1.0, and not allowing yet to configure TLS 1.1, nor TLS 1.2. http://www-01.ibm.com/support/docview.wss?uid=swg21578730 references specific crypto configurations to get granular enough to resolve issues within each TLS version, such as beast.



    Once upgraded and configured re-run sslscan, or alternatives if you would like to compare against sslscan such as testssl.sh.






    share|improve this answer



























      1














      Your output only references TLS 1.0, and disabling it refuses those disabled TLS 1.0 choices as it should. Refer to the DataPower references and documentation to support TLS 1.1 and TLS 1.2 as well as configuring cipher suites. Start with checking your firmware version and properly upgrading to better support the latest TLS configurations.



      Here is a reference for DataPower supporting TSL 1.1 and TLS 1.2 by default in firmware version 6. Your current version may not support anything but TLS 1.0, and not allowing yet to configure TLS 1.1, nor TLS 1.2. http://www-01.ibm.com/support/docview.wss?uid=swg21578730 references specific crypto configurations to get granular enough to resolve issues within each TLS version, such as beast.



      Once upgraded and configured re-run sslscan, or alternatives if you would like to compare against sslscan such as testssl.sh.






      share|improve this answer

























        1












        1








        1







        Your output only references TLS 1.0, and disabling it refuses those disabled TLS 1.0 choices as it should. Refer to the DataPower references and documentation to support TLS 1.1 and TLS 1.2 as well as configuring cipher suites. Start with checking your firmware version and properly upgrading to better support the latest TLS configurations.



        Here is a reference for DataPower supporting TSL 1.1 and TLS 1.2 by default in firmware version 6. Your current version may not support anything but TLS 1.0, and not allowing yet to configure TLS 1.1, nor TLS 1.2. http://www-01.ibm.com/support/docview.wss?uid=swg21578730 references specific crypto configurations to get granular enough to resolve issues within each TLS version, such as beast.



        Once upgraded and configured re-run sslscan, or alternatives if you would like to compare against sslscan such as testssl.sh.






        share|improve this answer













        Your output only references TLS 1.0, and disabling it refuses those disabled TLS 1.0 choices as it should. Refer to the DataPower references and documentation to support TLS 1.1 and TLS 1.2 as well as configuring cipher suites. Start with checking your firmware version and properly upgrading to better support the latest TLS configurations.



        Here is a reference for DataPower supporting TSL 1.1 and TLS 1.2 by default in firmware version 6. Your current version may not support anything but TLS 1.0, and not allowing yet to configure TLS 1.1, nor TLS 1.2. http://www-01.ibm.com/support/docview.wss?uid=swg21578730 references specific crypto configurations to get granular enough to resolve issues within each TLS version, such as beast.



        Once upgraded and configured re-run sslscan, or alternatives if you would like to compare against sslscan such as testssl.sh.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Dec 21 '15 at 19:13









        IancnordenIancnorden

        1175




        1175



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f743166%2fcipher-suites-supported-by-tls1-1-and-1-2%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            How to write a 12-bar blues melodyI-IV-V blues progressionHow to play the bridges in a standard blues progressionHow does Gdim7 fit in C# minor?question on a certain chord progressionMusicology of Melody12 bar blues, spread rhythm: alternative to 6th chord to avoid finger stretchChord progressions/ Root key/ MelodiesHow to put chords (POP-EDM) under a given lead vocal melody (starting from a good knowledge in music theory)Are there “rules” for improvising with the minor pentatonic scale over 12-bar shuffle?Confusion about blues scale and chords

            What if the end-user didn't have the required library?What is setup.py?What is a clean, pythonic way to have multiple constructors in Python?What does Ruby have that Python doesn't, and vice versa?What is the reason for having '//' in Python?How do I create a namespace package in Python?How to package shared objects that python modules depend on?setuptools vs. distutils: why is distutils still a thing?Navigation in Windows 10 vs code not going to virtualenv library when the same library is installed at user levelPython create package for local usePackaging a project that uses multiple python versionsWhy is permission denied on pip install except for when “--user” is included at end of command?

            Esgonzo ibérico Índice Descrición Distribución Hábitat Ameazas Notas Véxase tamén "Acerca dos nomes dos anfibios e réptiles galegos""Chalcides bedriagai"Chalcides bedriagai en Carrascal, L. M. Salvador, A. (Eds). Enciclopedia virtual de los vertebrados españoles. Museo Nacional de Ciencias Naturales, Madrid. España.Fotos