FAQ on App Service cipher suites

This post has been republished via RSS; it originally appeared at: Microsoft Tech Community - Latest Blogs - .

Q1: What are cipher suites and how do they work on App Service?

 

Q2: How to confirm the supported cipher suites on App Service server side?

 

Q3: Why does App Service support some weak cipher suites?

  • For the purpose of backward compatibility when someone is using a legacy browser, which usually requires weak cipher suites to establish an SSL connection. Otherwise, the client will meet SSL errors.

 

Q4: What has Azure App Service done to make it as secure as possible?

  • Azure Web App places the strongest and most secure cipher suites in the front of our cipher order.
  • The cipher suite order is in line with guidance from Azure Security.

 

Q5: How to disable some of the weak cipher suites?

Leave a Reply

Your email address will not be published. Required fields are marked *

*

This site uses Akismet to reduce spam. Learn how your comment data is processed.