Cloud SWG: Weak/Deprecated TLS Ciphers Support Removal

Resolved
Resolved

Please see the following links containing important information regarding supported Cipher Suites. This will be the final update for this incident:

Monitoring

As part of the recent Cloud SWG release, we have removed support for weak / deprecated TLS ciphers. We ask that clients communicating with the Cloud SWG Portal (including UPE updates) have support for at least one of these ciphers:

  • TLS 1.2 ECDHE-RSA-AES128-GCM-SHA256: ECDHE-RSA-AES256-GCM-SHA384: ECDHE-ECDSA-AES128-GCM-SHA256: ECDHE-ECDSA-AES256-GCM-SHA384: ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES256-SHA384: TLS_RSA_WITH_AES_256_CBC_SHA
  • TLS 1.3 TLS_AES_128_GCM_SHA256: TLS_AES_256_GCM_SHA384: TLS_CHACHA20_POLY1305_SHA256: TLS_AES_128_CCM_SHA256:TLS_AES_128_CCM_8_SHA256

Support

Questions? Contact technical support by visiting: https://support.broadcom.com/security

For service status and maintenance updates visit and subscribe to Broadcom Service Status: https://status.broadcom.com

Began at:

Affected components