View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0009814 | 10000-007: Profiles | Spec | public | 2024-09-04 06:47 | 2024-09-17 15:25 |
Reporter | Matthias Schulz | Assigned To | Paul Hunkar | ||
Priority | high | Severity | major | Reproducibility | always |
Status | assigned | Resolution | open | ||
Product Version | 1.04 | ||||
Summary | 0009814: Usage of weak TLS ciphersuites | ||||
Description | OPCUA 1.04 specifies TLS ciphersuites that are considered weak for various reasons. For a security point of view such ciphersuites shall be avoided and replaced by one that is recommened for state-of-the art products. Current mandatory ciphersuits: https://reference.opcfoundation.org/Core/Part7/v104/docs/6.6.160 https://reference.opcfoundation.org/Core/Part7/v104/docs/6.6.159 Here is a list of recommended ciphersuites: https://ciphersuite.info/cs/?security=recommended&sort=sec-desc Additionally, mbedTLS is dropping support for such weak ciphersuites in future versions: | ||||
Tags | Part 7 | ||||
Commit Version | 1.05.04 | ||||
Fix Due Date | 2024-09-22 | ||||
|
Recommendations now: TLS 1.2 TLS 1.3 |
|
Sounds good! |
|
What is your plan to deprecate the weak ciphers? Will there be a phase, where TLSRSA... ciphers are deprecated and the new ones already mandatory? In the end, the weak ciphers shall not be allowed anymore, alto to prevent downgrade attacks. |
Date Modified | Username | Field | Change |
---|---|---|---|
2024-09-04 06:47 | Matthias Schulz | New Issue | |
2024-09-04 06:47 | Matthias Schulz | Tag Attached: Part 7 | |
2024-09-04 14:11 | Randy Armstrong | Project | 10000-002: Security => 10000-007: Profiles |
2024-09-04 15:17 | Randy Armstrong | Note Added: 0021656 | |
2024-09-05 06:33 | Matthias Schulz | Note Added: 0021657 | |
2024-09-05 06:37 | Matthias Schulz | Note Added: 0021658 | |
2024-09-17 15:22 | Jim Luth | Assigned To | => Paul Hunkar |
2024-09-17 15:22 | Jim Luth | Status | new => assigned |
2024-09-17 15:25 | Jim Luth | Commit Version | => 1.05.04 |
2024-09-17 15:25 | Jim Luth | Fix Due Date | => 2024-09-22 |