Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

Sophos Email customers using IP-based mailflow rule connectors must migrate to certificate-based configuration by March 31st. To see if you're affected Click Here.

Enforced TLS: Available cipher suites

Dear Sophos-Community,

I am currently setting up a forced-TLS connection between a Sophos Email gateway with an email gateway of a different provider.

Unfortunately, we are experiencing a cipher mismatch. The Sophos gateway is offering the following cipher suites:

  • ECDHE-ECDSA-AES256-GCM-SHA384
  • ECDHE-ECDSA-CHACHA20-POLY1305
  • ECDHE-ECDSA-AES256-CCM8
  • ECDHE-ECDSA-AES256-CCM
  • ECDHE-ECDSA-AES128-GCM-SHA256
  • ECDHE-ECDSA-AES128-CCM8
  • ECDHE-ECDSA-AES128-CCM
  • ECDHE-ECDSA-AES256-SHA384
  • ECDHE-ECDSA-AES128-SHA256

Does anyone know if there are additional cipher suites available which can be added? The other gateway supports the following suites (all RSA related):

  • ECDHE-RSA-AES256-GCM-SHA384
  • ECDHE-RSA-AES256-SHA384
  • ECDHE-RSA-AES256-SHA
  • ECDHE-RSA-AES128-GCM-SHA256
  • ECDHE-RSA-AES128-SHA256
  • ECDHE-RSA-AES128-SHA

Thank you very much in advance!

Best regards

Markus



Added TAG
[edited by: Raphael Alganes at 11:22 AM (GMT -7) on 1 May 2024]
Parents Reply Children
No Data