SAP Knowledge Base Article - Preview

3797056 - TLS Cipher Disablement for Inbound Communication to SAP API Management

Symptom

As part of SAP's ongoing commitment to maintaining the highest security standards across its cloud platforms, SAP API Management is gradually deprecating weak TLS Profiles (TLS version, cipher suite, supported groups, signature algorithms, EKU requirements, etc.) for inbound TLS communication. Customers may receive notifications prior to such deprecations. This article aims to provide clarity on this topic.

As part of this initiative, the following TLS 1.2 cipher suites will be deprecated and removed:

Cipher Suite (IANA / JSSE name)OpenSSL name
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256DHE-RSA-AES128-GCM-SHA256
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384DHE-RSA-AES256-GCM-SHA384


Read more...

Environment

  • SAP Integration Suite
  • SAP API Management
  • SAP Business Technology Platform

Product

API Management all versions

Keywords

DHE, cipher, cipher suite, TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, API Management, APIM, API, Integration Suite , KBA , OPU-API-OD-OPS , Operations , Product Enhancement

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.