Skip to content

weak cryptographic method #9

@ricki-z

Description

@ricki-z

Result of the test for madavi.de (HTTP)
"… bieten schwache kryptografische Verfahren an (z.B. RC4, 56 Bit, ...)";"1 (100%)";"1 (100%)"
but I can't find a weak cipher in the following lists:

;;;;;"Supported CipherSuites";"All supported CipherSuites by this server";set;1;;;;;"ECDHE_RSA_WITH_AES_128_CBC_SHA256 => 1, ECDHE_RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_128_CBC_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA256 => 1, DHE_RSA_WITH_AES_256_CBC_SHA256 => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA384 => 1, DHE_RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_128_CBC_SHA256 => 1, DHE_RSA_WITH_AES_256_GCM_SHA384 => 1, ECDHE_RSA_WITH_AES_128_GCM_SHA256 => 1, ECDHE_RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_128_CBC_SHA => 1, DHE_RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_3DES_EDE_CBC_SHA => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA => 1"
;;;;;"Supported CipherSuites";"All supported CipherSuites by this server";set;1;;;;;"ECDHE_RSA_WITH_AES_128_CBC_SHA256 => 1, ECDHE_RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_128_CBC_SHA256 => 1, DHE_RSA_WITH_AES_128_GCM_SHA256 => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA384 => 1, RSA_WITH_AES_256_CBC_SHA256 => 1, DHE_RSA_WITH_AES_256_CBC_SHA256 => 1, DHE_RSA_WITH_AES_256_GCM_SHA384 => 1, RSA_WITH_AES_128_CBC_SHA256 => 1, ECDHE_RSA_WITH_AES_128_CBC_SHA => 1, ECDHE_RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_128_CBC_SHA => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA => 1, DHE_RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_3DES_EDE_CBC_SHA => 1"
;;;;;"Supported CipherSuites";"All supported CipherSuites by this server";set;1;;;;;"DHE_RSA_WITH_AES_128_CBC_SHA256 => 1, RSA_WITH_AES_128_CBC_SHA => 1, DHE_RSA_WITH_3DES_EDE_CBC_SHA => 1, DHE_RSA_WITH_AES_256_GCM_SHA384 => 1, RSA_WITH_3DES_EDE_CBC_SHA => 1, DHE_RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_AES_128_CBC_SHA256 => 1, DHE_RSA_WITH_AES_128_GCM_SHA256 => 1, DHE_RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_256_CBC_SHA256 => 1, RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_AES_256_CBC_SHA256 => 1"
;;;;;"Supported CipherSuites";"All supported CipherSuites by this server";set;1;;;;;"RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_3DES_EDE_CBC_SHA => 1, DHE_RSA_WITH_AES_256_CBC_SHA => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA => 1, ECDHE_RSA_WITH_AES_128_GCM_SHA256 => 1, ECDHE_RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_256_CBC_SHA256 => 1, DHE_RSA_WITH_AES_256_CBC_SHA256 => 1, DHE_RSA_WITH_AES_128_GCM_SHA256 => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA384 => 1, RSA_WITH_AES_128_CBC_SHA256 => 1, DHE_RSA_WITH_AES_256_GCM_SHA384 => 1, ECDHE_RSA_WITH_AES_256_GCM_SHA384 => 1, ECDHE_RSA_WITH_AES_128_CBC_SHA256 => 1, DHE_RSA_WITH_AES_128_CBC_SHA256 => 1"
;;;;;"Supported CipherSuites";"All supported CipherSuites by this server";set;1;;;;;"DHE_RSA_WITH_AES_256_GCM_SHA384 => 1, RSA_WITH_AES_128_CBC_SHA256 => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA384 => 1, DHE_RSA_WITH_AES_128_GCM_SHA256 => 1, DHE_RSA_WITH_AES_256_CBC_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA256 => 1, DHE_RSA_WITH_AES_128_CBC_SHA256 => 1, ECDHE_RSA_WITH_AES_256_GCM_SHA384 => 1, ECDHE_RSA_WITH_AES_128_CBC_SHA256 => 1, ECDHE_RSA_WITH_AES_256_CBC_SHA => 1, DHE_RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_3DES_EDE_CBC_SHA => 1, RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_AES_128_CBC_SHA => 1, ECDHE_RSA_WITH_AES_128_CBC_SHA => 1, ECDHE_RSA_WITH_AES_128_GCM_SHA256 => 1"
;;;;;"Supported CipherSuites";"All supported CipherSuites by this server";set;1;;;;;"DHE_RSA_WITH_AES_128_CBC_SHA256 => 1, RSA_WITH_AES_128_CBC_SHA => 1, DHE_RSA_WITH_3DES_EDE_CBC_SHA => 1, DHE_RSA_WITH_AES_256_GCM_SHA384 => 1, RSA_WITH_3DES_EDE_CBC_SHA => 1, RSA_WITH_AES_128_CBC_SHA256 => 1, DHE_RSA_WITH_AES_256_CBC_SHA => 1, DHE_RSA_WITH_AES_128_GCM_SHA256 => 1, DHE_RSA_WITH_AES_128_CBC_SHA => 1, RSA_WITH_AES_256_GCM_SHA384 => 1, DHE_RSA_WITH_AES_256_CBC_SHA256 => 1, RSA_WITH_AES_128_GCM_SHA256 => 1, RSA_WITH_AES_256_CBC_SHA => 1, RSA_WITH_AES_256_CBC_SHA256 => 1"

There are 3DES ciphers in the list for PCI compliance. Are these treated as week (string contains DES)?
The test on ssllab.com gives an "A+".

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions