SAP Knowledge Base Article - Preview

3657651 - Weak encryption algorithms with openssl - SAP Data Services

Symptom

How to eliminate weak encryption algorithms: DHE, 3DES, MD5, CBC, SHA and those that generate keys smaller than 2048 bits. 
After following KBA 2509691 - How to disable both SSLv2 and SSLv3 in Data Services   

Still seeing weak ciphers from scan:
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA256
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256


Read more...

Environment

Data Services 4.3, 2025

Keywords

Openssl, encryption, security , KBA , EIM-DS-SVR , Administration/Server , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.