AnsweredAssumed Answered

Which TLS cipher suite profile to use?

Question asked by Gunther Kochmann Employee on Jun 10, 2016
Latest reply on Jul 18, 2017 by Michael Kuchyt

Hi,

 

I came across this article SSL/TLS Cipher Profiles for Akamai Secure CDN while I was looking at the inquiry of an IT security department. This IT security department complained about this cipher suite with less than 128bits:

 

TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa)

 

The current setup is making use of the 'ak-akamai-pfs-supported' profile, which include the mentioned cipher suite.

 

However, even if we decide to move on to one of the latest recommended cipher suite profiles (ak-akamai-default-2016q1 or ak-pci-dss-3.1), that above mentioned cipher suite will be included.

 

What is the recommendation or option here, given the complaint by the IT security department?

 

Thanks,

Gunther

SSL/TLS Cipher Profiles for Akamai Secure CDN

Outcomes