Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How to disable weak ciphers

Mark Cogan
Contributor
August 2, 2019

First, I am already following the directions in this:

https://confluence.atlassian.com/kb/security-tools-report-the-default-ssl-ciphers-are-too-weak-755140945.html

We are seeing the following security issues:

SSH Weak Algorithms

arcfour
arcfour128
arcfour256

 

SSH Server CBC Mode Ciphers

3des-cbc
aes128-cbc
aes192-cbc
aes256-cbc
blowfish-cbc
cast128-cbc
rijndael-cbc@lysator.liu.se

 

SSH Weak MAC Algorithms

hmac-md5
hmac-md5-96
hmac-sha1-96

 

1 answer

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 14, 2019

It depends on what layer is providing your SSL.

If you are behind a proxy, consult the documentation on doing it for that proxy. 

If you are just using the Tomcat that Confluence runs on, then the question becomes what are you doing differently to what the document has said you should do, and why?

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events