Question

Disable SSL 2.0 and 3.0. Use TLS 1.2

  • 9 March 2022
  • 1 reply
  • 142 views

Userlevel 1
Badge +7

We have had a external penetration test done recently and they have advised that we disable SSL 2.0 and 3.0. Use TLS 1.2. is this possible in IFS specifically FSM release 6 update 10?

Also they advise we reconfigure the service to use a unique Diffie-Hellman moduli of 2048 bits or greater, is this ok?

BTW I know how to do these in IIS/Windows just worried that I will break the application or access. application to work

 


This topic has been closed for comments

1 reply

Userlevel 7
Badge +24

@Aaron.Sleight @Jon Reid Do we have guidance on the versions of SSL/TLS we use for each version and if these can be changed/ are compatible?