Collapse AllExpand All

18.8.5.1.3. TLSv1.2 Previous topic Parent topic Child topic Next topic

Currently are supported only protocols TLSv1.0 and higher, SSLv2 and SSLv3 are not permitted due to security issues. The default minimum RSA key length is 2048.
TLS version is configured in WBM menu:
Configuration > Security > Signaling and Payload Encryption (SPE) > click on TLS Ciphers for HFA > Edit TLS Cipher Configuration.
On following screen can be configured deployed TLS version, key agreement method, encryption algorithm and used mode of operation (see https://www.ietf.org/rfc/rfc5246.txt for more information about TLSv1.2).
IMPORTANT:
After changing and saving TLS HFA settings, CGW must be rebooted for the changes to take effect.

Figure 418. HFA SPE Configuration TLS

TLS_Ciphers_for_HFA_-2.png