Salesforce

ABL client default cipher suites for SSL

« Go Back

Information

 
TitleABL client default cipher suites for SSL
URL Nameabl-client-default-cipher-suites-for-ssl
Article Number000171765
EnvironmentProduct: OpenEdge
Version: 11.7.x, 12.x
OS: All supported platforms
Question/Problem Description

ABL client default ciphers list does not include all supported ciphers. Why some set of cipher suites has been picked vs another as defaults? Is this list going to be updated in the future release?

Supported ciphers for Progress OpenEdge clients:

  • AES128-SHA256:
  • AES256-SHA256:
  • DHE-RSA-AES128-SHA256:
  • AES128-GCM-SHA256:
  • DHE-RSA-A ES128-GCM-SHA256:
  • DHE-RSA-AES256-SHA256:
  • ADH-AES128-SHA256:
  • ADH-AES256-SHA256:
  • ADH-AES128-GCM -SHA256:
  • AES256-GCM-SHA384:
  • DHE-RSA-AES256-GCM-SHA384:
  • ADH-AES256-GCM-SHA384
Steps to Reproduce
Clarifying Information
The issue is with OE ABL client connecting to an external service.
Error MessageSecure Socket Layer (SSL) failure. error code 17424: SSL routines (9318)
Secure Socket Layer (SSL) failure. error code 336151568: SSL routines (9318)
Defect NumberEnhancement OPENEDGE-1568
Enhancement Number
Cause
The ABL client's default list of ciphers was incorrectly restricted by OE's use of the underlying TLS vendor. Why it was restricted is no longer the issue. What is important is that Progress has recognized the issue and is working to fix it so that customer's do not run into this issue again in the future. Once corrected, current expectation is that OE's default set of default ABL client ciphers will become inclusive of all the vendor's available ciphers. 
Resolution
Implemented in OE 12.2 where the client now supports all ciphers supported by OpenSSL.
Workaround
Notes
Keyword Phrase
Last Modified Date12/2/2022 12:02 PM

Powered by