ip ssl disable-weak-ciphers

Disables weak SSL or TLS cipher.
Syntax
ip ssl disable-weak-ciphers
no ip ssl disable-weak-ciphers
Command Default

Weak SSL or TLS cipher suites are disabled.

Parameters
disable-weak-ciphers
Disables weak SSL or TLS ciphers when configured.
Modes

Global configuration mode

Usage Guidelines

This command disables weak SSL/TLS cipher suites when the RUCKUS ICX device operates as a web server. The enabled cipher suites are: ECDHE-RSA-AES256-GCM-SHA384, ECDHE-RSA-AES128-GCM-SHA256, ECDHE-ECDSA-AES256-GCM-SHA384, and ECDHE-ECDSA-AES128-GCM-SHA256. The TLS connections are negotiated exclusively using these secure cipher suites.

The no form of the command removes the configuration.

Examples

The following example disables weak ciphers.

device# config
device(config)# ip ssl disable-weak-ciphers
History
Release version Command history
10.0.10h_cd1 This command is introduced.