Skip to content

TLS and HTTPS

Weak TLS cipher suites

Whether the server accepts a connection using a cipher suite that is considered broken or weak, such as RC4, 3DES, NULL, export-grade or anonymous ciphers.

Part of the External Security Check. Free during the preview.

What it checks

Whether the server accepts a connection using a cipher suite that is considered broken or weak, such as RC4, 3DES, NULL, export-grade or anonymous ciphers.

A pass means: Weak and broken cipher suites are refused.

Possible findings

Weak cipher suites accepted

Severity: MediumConfidence: ConfirmedKind: Security issue

What we found

The server accepted a connection using a cipher suite that is considered broken or weak.

Why it matters

Weak suites such as RC4, 3DES, NULL, export-grade or anonymous ciphers can let an attacker read or tamper with traffic under some conditions.

How to fix it

Restrict the server to modern AEAD cipher suites (AES-GCM, ChaCha20-Poly1305). Mozilla's SSL Configuration Generator produces a correct configuration for most servers.

References