Hi,
we are running RouterOS v6.47.10 on 60Ghz Dishes and according to our security policy we have to disable all known weak protocols, ciphers, algorithms and so on.
SSH is clean already (strong crypto did the job), but TLS is still an issue.
TLS is set to 1.2 only (/ip service set www-ssl tls-version=only-1.2),
but within TLS there are still weak cryptos active; see below the findings from our security scanner.
How do i disable this weak stuff?
Negotiated with the following insecure cipher suites:
TLS 1.2 ciphers:
TLS_ECDHE_RSA_WITH_RC4_128_SHA
TLS_RSA_WITH_RC4_128_MD5
TLS_RSA_WITH_RC4_128_SHA
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_RSA_WITH_AES_128_GCM_SHA256
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_RSA_WITH_AES_256_GCM_SHA384
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
TLS_RSA_WITH_RC4_128_MD5
TLS_RSA_WITH_RC4_128_SHA
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_3DES_EDE_CBC_SHA