cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
826
Views
5
Helpful
4
Replies

Expressway application vulnerability: SSL certificate is supporting TLS 1.0 and SHA1

ccg-collab1
Level 2
Level 2

Hi All,

 

We have expressway edge and core and their current version is 8.8. Security team told us that they receive notification about the SSL certificate is supporting TLS 1.0 and SHA1 which has a bad rating for vulnerability. May we know on how can we address it? 

 

I tried searching the latest version of expressway which is 8.10.2 and found below information.

8.10.2 tls info.JPG

 

From version 8.8 release note, i have seen this information below.

8.8 tls info.JPG

 

Appreciate if you can help us on how to resolve or address this issue of vulnerability regarding ssl certificate. Can we disable TLS 1.0 and SHA1 or do we need to upgrade the version of expressway to 8.10.2?

 

Thank you.

 

4 Replies 4

Patrick Sparkman
VIP Alumni
VIP Alumni
I recommend you upgrade to the most recent software version if you can, take advantage of new features and security patches. If you upgrade to X8.10 and later, you can set the minimum TLS version to 1.2. The SHA level for the certificate is set by the CA that signed the certificate, you should request a new certificate if your current one uses SHA1 which isn't supported anymore.

Hi Patrick,

 

Thank you so much for the recommendation. Am I correct to say that we can directly upgrade from X8.8 to X8.10.2?

Yes, you can upgrade directly, and no release key isn't required.

Great. Thank you so much. We will try to upgrade the expressway and update this discussion once done. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: