Summary
The security level of the IDR cipher ECDHE-RSA-AES256-SHA384 will be changed from HIGH to MEDIUM in INCOMING and OUTGOING connection encryption settings. This is planned for October 2023 release.
Details
INCOMING Connection
If you are using HIGH encryption settings for INCOMING connections and if the end user/API client machines do not have any other common cipher than ECDHE-RSA-AES256-SHA384, upgrade the machines to include ciphers from the following list.
- ECDHE-RSA-AES256-GCM-SHA384
- ECDHE-RSA-AES128-GCM-SHA256
- DHE-RSA-AES256-GCM-SHA384
- DHE-RSA-AES128-GCM-SHA256
OUTGOING Connection
If you are using HIGH encryption settings for OUTGING connections and if any of the configured proxy backend applications (HTTP Federation Proxy/Trusted Header) do not have any other common cipher than ECDHE-RSA-AES256-SHA384, upgrade the backend applications to include the ciphers from the following list.
- ECDHE-RSA-AES256-GCM-SHA384
- ECDHE-RSA-AES128-GCM-SHA256
- ECDHE-ECDSA-AES128-GCM-SHA256
- DHE-RSA-AES256-GCM-SHA384
- DHE-RSA-AES128-GCM-SHA256
If you are unable to upgrade the cipher ECDHE-RSA-AES256-SHA384 settings at client, configure the MEDIUM level and publish.
Related Articles
RSA Authentication Manager 8.x - Weak Ciphers Vulnerabilities found with Qualys Scan - Updated 1.51KNumber of Views What to expect during an RSA SecurID Access Identity Router (IDR)/Cluster software update 611Number of Views How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle 2.23KNumber of Views Failing to access Identity Router IDR Web resource after IDR v2.17 update 114Number of Views Authentication Manager 8.8 update breaks TLS connections; TLS Handshake error no cipher suites in common 72Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators