3 ms·
We upgraded to this, only to find it activates some new encryption modes (4 new GCM suites) that don't seem to function properly for us. Anyone else seen that i
by Robin_Message 12y ago
We upgraded to this, only to find it activates some new encryption modes (4 new GCM suites) that don't seem to function properly for us. Anyone else seen that issue?
(Technical details: If the client offer one of the suites, the server is accepting it in the ServerHello, but then RSTing the connection after the client sends their encrypted handshake, and the event log says "none of the cipher suites supported by the client application are supported by the server". Browser and curl don't use that suite, but Amazon ELB does.)
- duckhead814 12y agoYes, all of our AWS EC2 Windows instances sitting behind an ELB with the latest AWS Security Protocols will not communicate with the ELB after this update. I was able to fix this by reconfiguring the available cipher suites within IIS. Downloaded the IIS Crypto tool https://www.nartac.com/Products/IISCrypto/Default.aspx https://www.nartac.com/Products/IISCrypto/Default.aspx and applied their "Best Practices" which removed a bunch of insecure ciphers. After that the AWS ELB and IIS happily communicated.
- Robin_Message 12y agoThanks, nice to know there's not just something wrong with us! We made exactly the same fix with the same tool funnily enough.