Currently are supported only protocols TLSv1.0 and higher, SSLv2 and
SSLv3 are not permitted due to security issues. The default minimum RSA
key length is 2048.
TLS version is configured in WBM menu:
Configuration > Security > Signaling and Payload Encryption
(SPE) > click on TLS Ciphers for HFA > Edit TLS Cipher Configuration.
On following screen can be configured deployed TLS version, key agreement
method, encryption algorithm and used mode of operation (see https://www.ietf.org/rfc/rfc5246.txt
for more information about TLSv1.2).
IMPORTANT:
After changing and saving TLS HFA settings, CGW
must be rebooted for the changes to take effect.
Figure 418. HFA SPE Configuration TLS