Try OpenEdge Now
skip to main content
Core Business Services - Security and Auditing
Security : Security in OpenEdge : SSL Security : Changing the cryptographic protocol, ciphers, and certificates
 
Changing the cryptographic protocol, ciphers, and certificates
Progress OpenEdge supports TLS 1.2 as the default SSL protocol, and SHA 256 and SHA 384 as the default signed server certificates. The table in Supported protocols, ciphers, and certificates for Progress OpenEdge clients and servers lists the default ciphers. If you use a an OpenEdge client or a server prior to 11.6, you can update the default proptocol or cipher to one of the supported protocols or ciphers as listed in the tables below.
For example, if you use a client prior to 11.6, it uses TLS 1.0 as the default protocol and AES128-SHA as the default cipher. An OpenEdge 11.6 server uses TLS 1.2 as the default protocol and and the default ciphers are also different as listed in the table. Thus, for compatibility between these two versions, you must downgrade OpenEdge11.6 server to use TLS 1.0 and AES128-SHA. Also the 11.6 default server certificate must be changed from SHA256 to SHA1. See Changing the default protocols and ciphers for more details on changing the default.
* Supported protocols, ciphers, and certificates for Progress OpenEdge clients and servers
* Changing the default protocols and ciphers