This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cipher order and Key exchange parameters

Hello,

When we do a test on www.internet.nl/.../*ourdomain* we are getting the following errors back:

Key exchange parameters:

At least one of your mail servers supports insufficiently secure parameters for Diffie-Hellman key exchange.

DH-2048 insufficient

And the following:

Cipher order:

At least one of your mailservers does not enforce its own cipher preference ('I').

our domain : none

We are using Sophos UTM 9 version 9.707-5

How can we fix the errors on test?



This thread was automatically locked due to age.
Parents Reply Children
  • Hoi Wesley and welcome to the UTM Community!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks Bob Slight smile

    Require TLS Neg Sender Domains are only domain names no wildcard.

  • And, what happens if you put "Any" in '... Sender Domains'?

    TLS v1.2 is required in the EU, so, depending on your organization's correspondents, you may not need to worry about this.  In the USA, I see many domains that aren't at 1.2.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Anyipv4 and ipv6 are in now, problem is stil there.
    At least one of your mail servers supports insufficiently secure parameters for Diffie-Hellman key exchange.

    Technical details:

    Mail server (MX) Affected parameters Security level
    - DH-2048 insufficient


    And this one:

    Verdict:

    At least one of your mailservers does not enforce its own cipher preference ('I').
    Technical details:

    Mail server (MX) First found affected cipher pair
    - None
  • Ahhh, I didn't read closely enough.  I guess your TLS certificate is the problem.  You can generate a new one with a 4096-bit key to replace the one you're currently using.  Better luck with that, Wesley?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Put in a 4096 Bits certificate but same error message (2048 is generally aproved and a valid one, but we could always try)

    After using the new cert a reboot was done.

    Warning:

    Mail server (MX) First found affected cipher Status
    mx.*****.nl. AES256-GCM-SHA384

    phase out

    Errors:

    At least one of your mailservers does not enforce its own cipher preference ('I').

    Technical details:

    Mail server (MX) First found affected cipher pair
    mx.*****.nl. None

    Verdict:

    At least one of your mail servers supports insufficiently secure parameters for Diffie-Hellman key exchange.

    Technical details:

    Mail server (MX) Affected parameters Security level
    mx.*****.nl. DH-2048 insufficient

    When i check the test on the sophos.com domain i see the same errors are there.

    So i would think its a default setting from the Sophos UTM 9

  • So, it's the cert at mx.*****.nl.  What happens if you change that?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    Allready changed the certificate for a 4096 bit but stil the same errors.

    I contacted our certificate supplier but they are saying that its not the certificate but it need to be change on the UTM.

    Their translated message:

    Furthermore, the links you send are aimed at the Cipher Suites and/or Protocols that are used. This is not something that can be set on the certificate, but this is done at the server level. It is best to contact the supplier of the product for any adjustments.

  • OK, Wesley, my last guess.  What happens if you temporarily put "Any" in ' Require TLS Negotiation Hosts/Nets'?  If that doesn't do it, it's time to open a case with Sophos Support.

    Thanks for the link to www.internet.nl/mail/{domain} - great tool!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    This was the first thing we tried ;)

    Any4 and Any6 are listed.