Sophos Email customers using IP-based mailflow rule connectors must migrate to certificate-based configuration by March 31st. To see if you're affected Click Here.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Enforced TLS: Available cipher suites

Dear Sophos-Community,

I am currently setting up a forced-TLS connection between a Sophos Email gateway with an email gateway of a different provider.

Unfortunately, we are experiencing a cipher mismatch. The Sophos gateway is offering the following cipher suites:

  • ECDHE-ECDSA-AES256-GCM-SHA384
  • ECDHE-ECDSA-CHACHA20-POLY1305
  • ECDHE-ECDSA-AES256-CCM8
  • ECDHE-ECDSA-AES256-CCM
  • ECDHE-ECDSA-AES128-GCM-SHA256
  • ECDHE-ECDSA-AES128-CCM8
  • ECDHE-ECDSA-AES128-CCM
  • ECDHE-ECDSA-AES256-SHA384
  • ECDHE-ECDSA-AES128-SHA256

Does anyone know if there are additional cipher suites available which can be added? The other gateway supports the following suites (all RSA related):

  • ECDHE-RSA-AES256-GCM-SHA384
  • ECDHE-RSA-AES256-SHA384
  • ECDHE-RSA-AES256-SHA
  • ECDHE-RSA-AES128-GCM-SHA256
  • ECDHE-RSA-AES128-SHA256
  • ECDHE-RSA-AES128-SHA

Thank you very much in advance!

Best regards

Markus



This thread was automatically locked due to age.
Parents Reply Children
No Data