<-- Back

Weak TLS ciphers issues in Mendix Cloud

Issue

TLS 1.2 handshake failures occur when connecting to an endpoint of an application hosted on Mendix Cloud:

Could not create SSL/TLS secure channel

Environment

Applications hosted in Mendix Cloud

Cause

Mendix Cloud enforces security best practices, and no longer supports TLS ciphers that are considered weak. TLS signature algorithms and ciphers cannot be configured for a Mendix Cloud application, as they are managed by Mendix and based on the TLS Security Guidelines from NSC-NL.

Solution/Workaround

The Mendix Cloud Release Notes list the following supported ciphers:

TLSv1.3

  • TLS_AES_128_GCM_SHA256
  • TLS_AES_256_GCM_SHA384
  • TLS_CHACHA20_POLY1305_SHA256

TLSv1.2

  • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  • TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
  • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
  • TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
  • TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256

 

While these technologies are supported, Mendix Cloud domains currently only serve RSA certificates. Support for ECDSA certificates is on the road map, but is not yet available. Currently, only the following ciphers are actually compatible with applications hosted on Mendix Cloud:

TLSv1.3

  • TLS_AES_128_GCM_SHA256
  • TLS_AES_256_GCM_SHA384
  • TLS_CHACHA20_POLY1305_SHA256

TLSv1.2

  • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  •  

Ensure the client supports TLSv1.3 for improved security and performance. TLSv1.2 may still be used for compatibility, but should be restricted to the secure ciphers mentioned above. Weak ciphers should be disabled.

Internal information related

  • 240607, 210274 ,234852 ,211094
  • INFRA-1113

Additional information 

 

 

Have more questions? Submit a request

0 Comments

Article is closed for comments.

To provide feedback, please open a ticket here. Don't forget to include the article's URL along with the feedback you would like to provide.