Clarification: CBC based ciphers are found as weak in Testssl tool for tls 1.2v in Windows server 2019.

Raja Phanendra 0 Reputation points
2025-02-25T07:28:54.91+00:00

In Windows server 2019, Testssl tool found CBC based ciphersuites are weak. Are CBC based cipher suites are prone to vulnerable even if they are managed by Windows Schannel. Found an article stating that, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 may show up as weak when you performed an SSL report test. This is due to known attacks toward OpenSSL implementation. Dataverse uses Windows implementation that is not based on OpenSSL and therefore is not vulnerable. https://learn.microsoft.com/en-us/power-platform/admin/server-cipher-tls-requirements

Please provide the clarification for the above, whether the same is applicable to all the CBC based ciphersuites or not?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
4,002 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.