Community Discussions and Support
Security Update Required: Disabling Weak Ciphers / Security

Unfortunately I do.  I've requested access to the beta.  Thanks!

Unfortunately I do.  I've requested access to the beta.  Thanks!

I'm running Mercury 4.80.

ScanMyServer.com is reporting the following items with Mercury.  I have weak authenticators disabled unless SSL-secured, but is there a way to go a step further and address these?

Thanks 

 

Sweet32 Birthday Attacks on 64-bit Block Ciphers in TLS and OpenVPN (DES-CBC3)
<dl id="dt-list-1" class="dl-horizontal" style="box-sizing: border-box; margin-top: 0.5em; margin-bottom: 1em;"><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Summary</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">This test detects SSL ciphers DES-CBC3 supported by the remote service for encrypting communications.<br style="box-sizing: border-box;"><br style="box-sizing: border-box;"><div class="output" style="box-sizing: border-box; overflow: auto; padding: 0.5em; border: 1px solid;">Weak Cipher DES-CBC3 found: (Cipher: DES-CBC3-SHA|SSLv3|Kx=RSA|Au=RSA|Enc=3DES(168)|Mac=SHA1) (Cipher: DES-CBC3-SHA|TLSv1|Kx=RSA|Au=RSA|Enc=3DES(168)|Mac=SHA1)</div></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Port</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">imaps (993/tcp)</dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Solution</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">See solution found at: <a target="_blank" rel="nofollow" style="box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;" href="https://www.openssl.org/blog/blog/2016/08/24/sweet32/">https://www.openssl.org/blog/blog/2016/08/24/sweet32/</a></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">External sources</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;"><a target="_blank" rel="nofollow" style="box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;" href="https://sweet32.info/">https://sweet32.info/</a></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">CVE</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;"><a target="_new" style="box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;" href="http://www.securiteam.com/cgi-bin/cve.pl?cve=CVE-2016-2183">CVE-2016-2183</a></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Test ID</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">19146</dd></dl>

SSL Medium Strength Cipher Suites Supported
<dl id="dt-list-1" class="dl-horizontal" style="box-sizing: border-box; margin-top: 0.5em; margin-bottom: 1em;"><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Summary</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">The remote host supports the use of SSL ciphers that offer medium strength encryption, which we currently regard as those with key lengths at least 56 bits and less than 112 bits.<br style="box-sizing: border-box;"><br style="box-sizing: border-box;"><div class="output" style="box-sizing: border-box; overflow: auto; padding: 0.5em; border: 1px solid;">Here is the only medium strength SSL cipher supported by the remote server:<br style="box-sizing: border-box;">* Medium Strength Ciphers (&gt;= 56-bit and &lt; 112-bit key)<br style="box-sizing: border-box;">* SSLv3 - DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1 <br style="box-sizing: border-box;">* TLSv1 - DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1 <br style="box-sizing: border-box;">The fields above are:<br style="box-sizing: border-box;">* {OpenSSL ciphername}<br style="box-sizing: border-box;">* Kx={key exchange}<br style="box-sizing: border-box;">* Au={authentication}<br style="box-sizing: border-box;">* Enc={symmetric encryption method}<br style="box-sizing: border-box;">* Mac={message authentication code}<br style="box-sizing: border-box;">* {export flag}</div></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Port</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">imaps (993/tcp)</dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Solution</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">Reconfigure the affected application if possible to avoid use of medium strength ciphers.</dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">External sources</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;"><a target="_blank" rel="nofollow" style="box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;" href="http://support.microsoft.com/kb/245030">http://support.microsoft.com/kb/245030</a></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Test ID</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">12076</dd></dl>
Deprecated SSL Protocol Usage
<dl id="dt-list-1" class="dl-horizontal" style="box-sizing: border-box; margin-top: 0.5em; margin-bottom: 1em;"><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Summary</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">The remote service accepts connections encrypted using SSLv2 and/or SSLv3, which reportedly suffers from several cryptographic flaws and has been deprecated for several years. An attacker may be able to exploit these issues to conduct man-in-the-middle attacks or decrypt communications between the affected service and clients.<br style="box-sizing: border-box;"><br style="box-sizing: border-box;"><div class="output" style="box-sizing: border-box; overflow: auto; padding: 0.5em; border: 1px solid;">SSLv3</div></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Port</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">imaps (993/tcp)</dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Solution</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">Consult the application's documentation to disable SSL 2.0 and SSL 3.0, and use TLS 1.0 or newer.</dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">External sources</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;"><a target="_blank" rel="nofollow" style="box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;" href="http://www.schneier.com/paper-ssl.pdf">http://www.schneier.com/paper-ssl.pdf</a></dd><dt style="box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;">Test ID</dt><dd style="box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;">9329</dd></dl>

 

&lt;p&gt;I&#039;m running Mercury 4.80.&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;ScanMyServer.com is reporting the following items with Mercury.&amp;nbsp; I have weak authenticators disabled unless SSL-secured, but is there a way to go a step further and address these?&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;Thanks&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;timeline-item clearfix&quot; style=&quot;box-sizing: border-box; position: relative; margin-bottom: 8px; color: rgb(57, 57, 57); font-family: Roboto, sans-serif; font-size: 13px;&quot;&gt;&lt;div class=&quot;widget-box&quot; style=&quot;box-sizing: border-box; box-shadow: none; padding: 0px; margin: 0px 0px 0px 60px; border: 1px solid rgb(204, 204, 204); background-color: rgb(243, 243, 243); color: rgb(97, 97, 97); position: relative; max-width: none;&quot;&gt;&lt;div class=&quot;widget-header header-color-orange widget-header-small&quot; style=&quot;box-sizing: content-box; position: relative; min-height: 31px; background: linear-gradient(rgb(255, 255, 255) 0px, rgb(238, 238, 238) 100%) repeat-x rgb(247, 247, 247); color: rgb(102, 159, 199); border-bottom: 1px solid rgb(221, 221, 221); padding-left: 10px;&quot;&gt;&lt;h5 class=&quot;smaller&quot; style=&quot;box-sizing: border-box; font-family: &#039;Open Sans&#039;, &#039;Helvetica Neue&#039;, Helvetica, Arial, sans-serif; font-weight: 400; line-height: 1.1; color: inherit; margin-top: 10px; margin-bottom: 10px; font-size: 14px;&quot;&gt;Sweet32 Birthday Attacks on 64-bit Block Ciphers in TLS and OpenVPN (DES-CBC3)&lt;/h5&gt;&lt;span class=&quot;widget-toolbar&quot; style=&quot;box-sizing: border-box; display: inline-block; padding: 0px 10px; line-height: 29px; float: right; position: relative;&quot;&gt;&lt;a data-action=&quot;collapse&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(170, 170, 170); text-decoration-line: none; font-size: 14px; margin: 0px 1px; display: inline-block; padding: 0px; line-height: 24px; cursor: pointer; transition: transform 0.1s ease 0s;&quot; href=&quot;https://scanmyserver.com/my_account/?#&quot;&gt;&lt;span class=&quot;ace-icon fa fa-chevron-up&quot; style=&quot;box-sizing: border-box; display: inline-block; font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; line-height: 1; font-family: FontAwesome; font-size: inherit; text-rendering: auto; -webkit-font-smoothing: antialiased; text-align: center; margin-right: 0px;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;widget-body&quot; style=&quot;box-sizing: border-box; background-color: transparent;&quot;&gt;&lt;div class=&quot;widget-main&quot; style=&quot;box-sizing: border-box; padding: 12px; margin: 0px; position: relative; max-width: none; border-bottom-width: 0px;&quot;&gt;&lt;dl id=&quot;dt-list-1&quot; class=&quot;dl-horizontal&quot; style=&quot;box-sizing: border-box; margin-top: 0.5em; margin-bottom: 1em;&quot;&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Summary&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;This test detects SSL ciphers DES-CBC3 supported by the remote service for encrypting communications.&lt;br style=&quot;box-sizing: border-box;&quot;&gt;&lt;br style=&quot;box-sizing: border-box;&quot;&gt;&lt;div class=&quot;output&quot; style=&quot;box-sizing: border-box; overflow: auto; padding: 0.5em; border: 1px solid;&quot;&gt;Weak Cipher DES-CBC3 found: (Cipher: DES-CBC3-SHA|SSLv3|Kx=RSA|Au=RSA|Enc=3DES(168)|Mac=SHA1) (Cipher: DES-CBC3-SHA|TLSv1|Kx=RSA|Au=RSA|Enc=3DES(168)|Mac=SHA1)&lt;/div&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Port&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;imaps (993/tcp)&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Solution&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;See solution found at:&amp;nbsp;&lt;a target=&quot;_blank&quot; rel=&quot;nofollow&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;&quot; href=&quot;https://www.openssl.org/blog/blog/2016/08/24/sweet32/&quot;&gt;https://www.openssl.org/blog/blog/2016/08/24/sweet32/&lt;/a&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;External sources&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;&lt;a target=&quot;_blank&quot; rel=&quot;nofollow&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;&quot; href=&quot;https://sweet32.info/&quot;&gt;https://sweet32.info/&lt;/a&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;CVE&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;&lt;a target=&quot;_new&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;&quot; href=&quot;http://www.securiteam.com/cgi-bin/cve.pl?cve=CVE-2016-2183&quot;&gt;CVE-2016-2183&lt;/a&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Test ID&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;19146&lt;/dd&gt;&lt;/dl&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;timeline-item clearfix&quot; style=&quot;box-sizing: border-box; position: relative; margin-bottom: 8px; color: rgb(57, 57, 57); font-family: Roboto, sans-serif; font-size: 13px;&quot;&gt; &lt;/div&gt;&lt;div class=&quot;timeline-item clearfix&quot; style=&quot;box-sizing: border-box; position: relative; margin-bottom: 8px; color: rgb(57, 57, 57); font-family: Roboto, sans-serif; font-size: 13px;&quot;&gt;&lt;div class=&quot;timeline-info&quot; style=&quot;box-sizing: border-box; float: left; width: 60px; text-align: center; position: relative;&quot;&gt;&lt;i class=&quot;timeline-indicator icon-circle btn btn-warning no-hover&quot; style=&quot;box-sizing: border-box; display: inline-block; padding: 0px; margin: 0px; font-size: 16px; line-height: 30px; white-space: nowrap; vertical-align: middle; touch-action: manipulation; cursor: default; user-select: none; border-radius: 100%; transition: background-color 0.15s ease 0s, border-color 0.15s ease 0s, opacity 0.15s ease 0s; position: relative; opacity: 1; height: 36px; width: 36px; background-image: none !important; border: 3px solid rgb(255, 255, 255) !important; color: rgb(255, 255, 255) !important; background-color: rgb(255, 183, 82) !important; text-shadow: none !important; box-shadow: none !important;&quot;&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;widget-box&quot; style=&quot;box-sizing: border-box; box-shadow: none; padding: 0px; margin: 0px 0px 0px 60px; border: 1px solid rgb(204, 204, 204); background-color: rgb(243, 243, 243); color: rgb(97, 97, 97); position: relative; max-width: none;&quot;&gt;&lt;div class=&quot;widget-header header-color-orange widget-header-small&quot; style=&quot;box-sizing: content-box; position: relative; min-height: 31px; background: linear-gradient(rgb(255, 255, 255) 0px, rgb(238, 238, 238) 100%) repeat-x rgb(247, 247, 247); color: rgb(102, 159, 199); border-bottom: 1px solid rgb(221, 221, 221); padding-left: 10px;&quot;&gt;&lt;h5 class=&quot;smaller&quot; style=&quot;box-sizing: border-box; font-family: &#039;Open Sans&#039;, &#039;Helvetica Neue&#039;, Helvetica, Arial, sans-serif; font-weight: 400; line-height: 1.1; color: inherit; margin-top: 10px; margin-bottom: 10px; font-size: 14px;&quot;&gt;SSL Medium Strength Cipher Suites Supported&lt;/h5&gt;&lt;span class=&quot;widget-toolbar&quot; style=&quot;box-sizing: border-box; display: inline-block; padding: 0px 10px; line-height: 29px; float: right; position: relative;&quot;&gt;&lt;a data-action=&quot;collapse&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(170, 170, 170); text-decoration-line: none; font-size: 14px; margin: 0px 1px; display: inline-block; padding: 0px; line-height: 24px; cursor: pointer; transition: transform 0.1s ease 0s;&quot; href=&quot;https://scanmyserver.com/my_account/?#&quot;&gt;&lt;span class=&quot;ace-icon fa fa-chevron-up&quot; style=&quot;box-sizing: border-box; display: inline-block; font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; line-height: 1; font-family: FontAwesome; font-size: inherit; text-rendering: auto; -webkit-font-smoothing: antialiased; text-align: center; margin-right: 0px;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;widget-body&quot; style=&quot;box-sizing: border-box; background-color: transparent;&quot;&gt;&lt;div class=&quot;widget-main&quot; style=&quot;box-sizing: border-box; padding: 12px; margin: 0px; position: relative; max-width: none; border-bottom-width: 0px;&quot;&gt;&lt;dl id=&quot;dt-list-1&quot; class=&quot;dl-horizontal&quot; style=&quot;box-sizing: border-box; margin-top: 0.5em; margin-bottom: 1em;&quot;&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Summary&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;The remote host supports the use of SSL ciphers that offer medium strength encryption, which we currently regard as those with key lengths at least 56 bits and less than 112 bits.&lt;br style=&quot;box-sizing: border-box;&quot;&gt;&lt;br style=&quot;box-sizing: border-box;&quot;&gt;&lt;div class=&quot;output&quot; style=&quot;box-sizing: border-box; overflow: auto; padding: 0.5em; border: 1px solid;&quot;&gt;Here is the only medium strength SSL cipher supported by the remote server:&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* Medium Strength Ciphers (&amp;gt;= 56-bit and &amp;lt; 112-bit key)&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* SSLv3 - DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1&amp;nbsp;&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* TLSv1 - DES-CBC-SHA Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1&amp;nbsp;&lt;br style=&quot;box-sizing: border-box;&quot;&gt;The fields above are:&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* {OpenSSL ciphername}&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* Kx={key exchange}&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* Au={authentication}&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* Enc={symmetric encryption method}&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* Mac={message authentication code}&lt;br style=&quot;box-sizing: border-box;&quot;&gt;* {export flag}&lt;/div&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Port&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;imaps (993/tcp)&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Solution&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;Reconfigure the affected application if possible to avoid use of medium strength ciphers.&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;External sources&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;&lt;a target=&quot;_blank&quot; rel=&quot;nofollow&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;&quot; href=&quot;http://support.microsoft.com/kb/245030&quot;&gt;http://support.microsoft.com/kb/245030&lt;/a&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Test ID&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;12076&lt;/dd&gt;&lt;/dl&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;timeline-item clearfix&quot; style=&quot;box-sizing: border-box; position: relative; margin-bottom: 8px; color: rgb(57, 57, 57); font-family: Roboto, sans-serif; font-size: 13px;&quot;&gt;&lt;div class=&quot;timeline-info&quot; style=&quot;box-sizing: border-box; float: left; width: 60px; text-align: center; position: relative;&quot;&gt;&lt;i class=&quot;timeline-indicator icon-circle btn btn-warning no-hover&quot; style=&quot;box-sizing: border-box; display: inline-block; padding: 0px; margin: 0px; font-size: 16px; line-height: 30px; white-space: nowrap; vertical-align: middle; touch-action: manipulation; cursor: default; user-select: none; border-radius: 100%; transition: background-color 0.15s ease 0s, border-color 0.15s ease 0s, opacity 0.15s ease 0s; position: relative; opacity: 1; height: 36px; width: 36px; background-image: none !important; border: 3px solid rgb(255, 255, 255) !important; color: rgb(255, 255, 255) !important; background-color: rgb(255, 183, 82) !important; text-shadow: none !important; box-shadow: none !important;&quot;&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;widget-box&quot; style=&quot;box-sizing: border-box; box-shadow: none; padding: 0px; margin: 0px 0px 0px 60px; border: 1px solid rgb(204, 204, 204); background-color: rgb(242, 246, 249); color: rgb(89, 92, 102); position: relative; max-width: none;&quot;&gt;&lt;div class=&quot;widget-header header-color-orange widget-header-small&quot; style=&quot;box-sizing: content-box; position: relative; min-height: 31px; background: linear-gradient(rgb(255, 255, 255) 0px, rgb(238, 238, 238) 100%) repeat-x rgb(247, 247, 247); color: rgb(102, 159, 199); border-bottom: 1px solid rgb(221, 221, 221); padding-left: 10px;&quot;&gt;&lt;h5 class=&quot;smaller&quot; style=&quot;box-sizing: border-box; font-family: &#039;Open Sans&#039;, &#039;Helvetica Neue&#039;, Helvetica, Arial, sans-serif; font-weight: 400; line-height: 1.1; color: inherit; margin-top: 10px; margin-bottom: 10px; font-size: 14px;&quot;&gt;Deprecated SSL Protocol Usage&lt;/h5&gt;&lt;span class=&quot;widget-toolbar&quot; style=&quot;box-sizing: border-box; display: inline-block; padding: 0px 10px; line-height: 29px; float: right; position: relative;&quot;&gt;&lt;a data-action=&quot;collapse&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(170, 170, 170); text-decoration-line: none; font-size: 14px; margin: 0px 1px; display: inline-block; padding: 0px; line-height: 24px; cursor: pointer; transition: transform 0.1s ease 0s;&quot; href=&quot;https://scanmyserver.com/my_account/?#&quot;&gt;&lt;span class=&quot;ace-icon fa fa-chevron-up&quot; style=&quot;box-sizing: border-box; display: inline-block; font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; line-height: 1; font-family: FontAwesome; font-size: inherit; text-rendering: auto; -webkit-font-smoothing: antialiased; text-align: center; margin-right: 0px;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;widget-body&quot; style=&quot;box-sizing: border-box; background-color: transparent;&quot;&gt;&lt;div class=&quot;widget-main&quot; style=&quot;box-sizing: border-box; padding: 12px; margin: 0px; position: relative; max-width: none; border-bottom-width: 0px;&quot;&gt;&lt;dl id=&quot;dt-list-1&quot; class=&quot;dl-horizontal&quot; style=&quot;box-sizing: border-box; margin-top: 0.5em; margin-bottom: 1em;&quot;&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Summary&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;The remote service accepts connections encrypted using SSLv2 and/or SSLv3, which reportedly suffers from several cryptographic flaws and has been deprecated for several years. An attacker may be able to exploit these issues to conduct man-in-the-middle attacks or decrypt communications between the affected service and clients.&lt;br style=&quot;box-sizing: border-box;&quot;&gt;&lt;br style=&quot;box-sizing: border-box;&quot;&gt;&lt;div class=&quot;output&quot; style=&quot;box-sizing: border-box; overflow: auto; padding: 0.5em; border: 1px solid;&quot;&gt;SSLv3&lt;/div&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Port&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;imaps (993/tcp)&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Solution&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;Consult the application&#039;s documentation to disable SSL 2.0 and SSL 3.0, and use TLS 1.0 or newer.&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;External sources&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;&lt;a target=&quot;_blank&quot; rel=&quot;nofollow&quot; style=&quot;box-sizing: border-box; background-color: transparent; color: rgb(51, 122, 183); text-decoration-line: none; cursor: pointer;&quot; href=&quot;http://www.schneier.com/paper-ssl.pdf&quot;&gt;http://www.schneier.com/paper-ssl.pdf&lt;/a&gt;&lt;/dd&gt;&lt;dt style=&quot;box-sizing: border-box; line-height: 1.42857; font-weight: 700; float: left; width: 160px; overflow: hidden; clear: left; text-align: right; text-overflow: ellipsis; white-space: nowrap;&quot;&gt;Test ID&lt;/dt&gt;&lt;dd style=&quot;box-sizing: border-box; line-height: 1.42857; margin-left: 180px; padding-left: 1em;&quot;&gt;9329&lt;/dd&gt;&lt;/dl&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

In the configuration of the IMAP Server on SSL tab you have enabled (depreciated) direct-connect-SSL on port 993. Disable it after changing the mailclient(s) to TLS / StartTLS on Port 143. Should at least resolv problem 3.

The others I don't know ...

bye    Olaf

 

&lt;p&gt;In the configuration of the IMAP Server on SSL tab you have enabled (depreciated) direct-connect-SSL on port 993. Disable it after changing the mailclient(s) to TLS / StartTLS on Port 143. Should at least resolv problem 3.&lt;/p&gt;&lt;p&gt;The others I don&#039;t know ...&lt;/p&gt;&lt;p&gt;bye &amp;nbsp;&amp;nbsp; Olaf&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

Do you really need imap-access from the world? If not then i suggest to use a vpn or ask http://community.pmail.com/members/Rolf+Lindby.aspx for a link to the new beta version. Or you could use stunnel once again...

Do you really need imap-access from the world? If not then i suggest to use a vpn or ask&amp;nbsp;http://community.pmail.com/members/Rolf+Lindby.aspx for a link to the new beta version. Or you could use stunnel once again...
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft