Issue
TLS 1.2 handshake failures occur when connecting to an endpoint of an application hosted on Mendix Cloud:
Could not create SSL/TLS secure channelEnvironment
Applications hosted in Mendix Cloud
Cause
Mendix Cloud enforces security best practices, and no longer supports TLS ciphers that are considered weak. TLS signature algorithms and ciphers cannot be configured for a Mendix Cloud application, as they are managed by Mendix and based on the TLS Security Guidelines from NSC-NL.
Solution/Workaround
The Mendix Cloud Release Notes list the following supported ciphers:
TLSv1.3
- TLS_AES_128_GCM_SHA256
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256
TLSv1.2
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
- TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256
While these technologies are supported, Mendix Cloud domains currently only serve RSA certificates. Support for ECDSA certificates is on the road map, but is not yet available. Currently, only the following ciphers are actually compatible with applications hosted on Mendix Cloud:
TLSv1.3
- TLS_AES_128_GCM_SHA256
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256
TLSv1.2
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Ensure the client supports TLSv1.3 for improved security and performance. TLSv1.2 may still be used for compatibility, but should be restricted to the secure ciphers mentioned above. Weak ciphers should be disabled.
Internal information related
- 240607, 210274 ,234852 ,211094
- INFRA-1113
Additional information
- Mendix documentation:
- Related KBA: How to Address SSL/TLS Weak Key Exchange Supported Issue
0 Comments