1.9 SSL Strong Algorithm - b) ciphersuite

Information

There is a security risk to the ssl lower versions of the equipment. The device can be configured to support higher versions and algorithms only to reduce the connection risk of the ZTE Router Platform series products.

Solution

1. SSL must bound PKI profile, the bounded PKI profile needs to import a legal and valid CA certificate
2. TLS(SSL) version is recommended to be greater than TLS v1.2, at least not less than TLS v1.1.
3. TLS algorithm does not contain insecure algorithms, which include: CBC, SHA1, MD5
4. Disable renegotiate

ZXR10(config-ssl-context-zte1)# ciphersuite aes-128-gcm-sha256 aes-256-gcm-sha384 dhe-rsa-aes-128-gcm-sha256 ecc-sm4-sm3 ecdhe-rsa-aes-128-gcm-sha256 ecdhe-rsa-aes-256-gcm-sha384 ecdhe-sm4-sm3 tls_aes_128_gcm_sha256

See Also

https://support.zte.com.cn/support/doccenter/DocumentProductHandBookDetail.aspx?sid=102&id=30768582&type=docfeedback