WebInterface Encryption SSL
This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
WebInterface Encryption SSL
Model :
Hardware Version :
Firmware Version :
ISP :
Hi there,
I have purchased a T2600G-28TS Managed Switch.
I want to enable SSL for the Webinterface. At this point enabling the WebInterface is considered as totally broken and insecure.
For the Protocol there is only SSLv3/TLSv1 which is basically the same protocol. At best this can be called outdated if not a security risk. I am missing TLSv1.1 and TLSv2 and TLSv2+
For the Cipher there is only RC4, DES and TripleDES with MD5 and SHA available. This is considered to be totally broken for a decade or longer.
RC4 is prohibited from IETF for TLSv1 see RFC7465
DES was disallowed in 1999 and replaced by 3DES
NIST considers 3DES as low as 80 Bits security key length.
MD5 is insecure and is known as craced since 2004.
SHA/SHA1 is also known as broken.
Please remove all these borked ciphers, message digest and protocols and replace with an up to date version.
And replace in the next firmware update with cipherstings containing:
RSA, AES128, AES256, SHA256, SHA3xx, TLS1.1, TLS1.2, TLS1.2+, DHE, ECDHE, Chacha20, poly1305
best regards
tags: ssl, aes, des, 3des, md5, sha, sha1, tls, cipherstring, cipher, message digest, des, security, webinterface, webgui
Hardware Version :
Firmware Version :
ISP :
Hi there,
I have purchased a T2600G-28TS Managed Switch.
I want to enable SSL for the Webinterface. At this point enabling the WebInterface is considered as totally broken and insecure.
For the Protocol there is only SSLv3/TLSv1 which is basically the same protocol. At best this can be called outdated if not a security risk. I am missing TLSv1.1 and TLSv2 and TLSv2+
For the Cipher there is only RC4, DES and TripleDES with MD5 and SHA available. This is considered to be totally broken for a decade or longer.
RC4 is prohibited from IETF for TLSv1 see RFC7465
DES was disallowed in 1999 and replaced by 3DES
NIST considers 3DES as low as 80 Bits security key length.
MD5 is insecure and is known as craced since 2004.
SHA/SHA1 is also known as broken.
Please remove all these borked ciphers, message digest and protocols and replace with an up to date version.
And replace in the next firmware update with cipherstings containing:
RSA, AES128, AES256, SHA256, SHA3xx, TLS1.1, TLS1.2, TLS1.2+, DHE, ECDHE, Chacha20, poly1305
best regards
tags: ssl, aes, des, 3des, md5, sha, sha1, tls, cipherstring, cipher, message digest, des, security, webinterface, webgui