Skip to main content

Sweet32 (CVE-2016-2183)

Comments

3 comments

  • cPanelMichael
    Hello, The report from Trustwave does suggest removing all DES and 3DES-related ciphers, so your example is correct if that's what they require for compliance. You can read the OpenSSL article about this specific vulnerability on their website at: The SWEET32 Issue, CVE-2016-2183 - OpenSSL Blog There are some comments under the article regarding Trustwave that you may want to review. Thank you.
    0
  • Kent Brockman
    Hello guys. I was about to ask the same question, cause removing all DES and 3DES-related ciphers will match the default config of ciphers proposed by cPanel. My question is... what browsers would become unable to open secured sites if those ciphers are removed?
    0
  • cPanelMichael
    My question is... what browsers would become unable to open secured sites if those ciphers are removed?

    Hello @Kent Brockman, There might be other examples of browsers using 3DES on end-of-life operating systems, however from what I've read this is only going to affect Windows XP users with IE6 or IE8. Thank you.
    0

Please sign in to leave a comment.