IBM Support

Do not enable weak cipher suites for IBM DataPower Gateway appliances

Flashes (Alerts)


Abstract

With the recent attention to Factoring Attack on RSA-EXPORT keys that is referred to as FREAK,do not enable weak or export-level cipher suites.

Content

IBM DataPower Gateway by default disables RSA-EXPORT cipher suites. Verify that you have not enabled the RSA-EXPORT ciphers suites.

By default, the Ciphers property of Crypto Profile objects has the following value.
HIGH:MEDIUM:!aNULL:!eNULL:@STRENGTH

If you overrode the default configuration, ensure that you do not to include strings or ciphers that list weak RSA Export ciphers.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"Component":"General","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"7.7;7.6;7.5.2;7.5.1;7.5;","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
25 September 2022

UID

swg21699042