← Go back to Papirfly Status

Ending support for CBC ciphers in TLS connections to Papirfly services

November 28, 2023 at 14:57 UTC


Announcement

On 2023-12-18 at 06:00 CET, Papirfly will end support of cipher suites using the Cipher Block Chaining (CBC) mode of operation on hosting environments. These cipher suites are known to be susceptible to attacks such as padding oracle attack, which can lead to data leaks and other security issues.

For a list of TLS protocols and cipher suites that will be supported on each hosting environment after the above date, please consult the relevant section below.

How does this affect you?

Browser support

Most modern browsers, including Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari support strong ciphers. We recommend updating your browser to the most recent version available.

Applications and API access

Check that support for strong ciphers, such as GCM, is enabled in your application.

Cloud hosting environment (AWS)

All protocols and ciphers listed under the TLSv1.2_2021 policy column in the Supported protocols and ciphers between viewers and CloudFront document will be supported on our cloud hosting environment (AWS).

On-prem hosting environment (Lan-x)

The protocols and corresponding cipher suites listed below will be supported in our on-prem production environment.

Supported TLS protocols

Supported ECDSA ciphers

Supported RSA ciphers

Have any questions or need help?

Contact Papirfly Support

Changelog

2023-11-30: Delayed the configuration change until the planned scheduled maintenance window the following Monday.