Jun 02, 2014 · SSLv3.0/TLSv1.0 Protocol Weak CBC Mode Vulnerability port 8443/tcp over SSL RC4-SHA ECDHE-RSA-DES-CBC3-SHA SSLv3

Table 1. Cipher suite definitions for SSL V2; Cipher number Description FIPS 140-2 Base security level FMID HCPT410 Security level 3 FMID JCPT411; 1: 128-bit RC4 encryption with MD5 message authentication (128-bit secret key) DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1 EXP1024-DES-CBC-SHA Kx=RSA(1024) Au=RSA Enc=DES(56) Mac=SHA1 export EXP1024-RC4-SHA Kx=RSA(1024) Au=RSA Enc=RC4(56) Mac=SHA1 export DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1 I haven't been able to find much in the way of documentation as to how to do this. Remarks. Both field names and values are based on the TLS Cipher Suites list from the Internet Assigned Numbers Authority (IANA). This enumeration represents values that were known at the time a specific version of .NET was released. Search results "TLS_RSA_WITH_3DES_EDE_CBC_SHA" Ordering . Relevancy TLS Cipher Suites in Windows 10 v1809. 10/09/2018; 3 minutes to read; In this article. Cipher suites can only be negotiated for TLS versions which support them. ssl cipher tlsv1.2 custom "AES256-SHA:AES128-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:DES-CBC3-SHA:DES-CBC-SHA" ssl cipher dtlsv1 custom "AES256-SHA:AES128-SHA" ssl dh-group group2 ssl ecdh-group group19 ssl trust-point NEW-Self-Signed outside ssl certificate-authentication fca-timeout 2 . and still have the same problem with mobile phones And to add DES-CBC-SHA cipher to pyopenssl list of default ciphers: requests.packages.urllib3.contrib.pyopenssl.DEFAULT_SSL_CIPHER_LIST += ':DES-CBC-SHA' But connecton from Python 2.7.12 still failed with the same error:

ssl cipher tlsv1.2 custom "AES256-SHA:AES128-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:DES-CBC3-SHA:DES-CBC-SHA" ssl cipher dtlsv1 custom "AES256-SHA:AES128-SHA" ssl dh-group group2 ssl ecdh-group group19 ssl trust-point NEW-Self-Signed outside ssl certificate-authentication fca-timeout 2 . and still have the same problem with mobile phones

Aug 18, 2017

Quality of protection levels - publib.boulder.ibm.com

(**) Tested with default settings. Some platforms can be manually configured to enable more features and better security.