Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cipher order and Key exchange parameters

Hello,

When we do a test on www.internet.nl/.../*ourdomain* we are getting the following errors back:

Key exchange parameters:

At least one of your mail servers supports insufficiently secure parameters for Diffie-Hellman key exchange.

DH-2048 insufficient

And the following:

Cipher order:

At least one of your mailservers does not enforce its own cipher preference ('I').

our domain : none

We are using Sophos UTM 9 version 9.707-5

How can we fix the errors on test?



This thread was automatically locked due to age.
Parents Reply
  • Hi Bob,

    Allready changed the certificate for a 4096 bit but stil the same errors.

    I contacted our certificate supplier but they are saying that its not the certificate but it need to be change on the UTM.

    Their translated message:

    Furthermore, the links you send are aimed at the Cipher Suites and/or Protocols that are used. This is not something that can be set on the certificate, but this is done at the server level. It is best to contact the supplier of the product for any adjustments.

Children