Weak Cipher Strength with EM and SSL ?
Please pardon if I have posted this in the wrong forum, but this seemed the most apppropriate. We have an instance of Oracle 11g with Enterprise Manager accessible from https://server:1158/em. The network security guys just presented me with a system vilnerability scan which states that the application using SSL over port 1158 is using LOW STRENGTH Ciphers. We are required to meet government standards, so I'm thinking that anything less than 256-bit is "weak". Has anyone else ran into this and know how to fix it? I know there are Windows registry settings that would affect IIS, but I'm not sure if those settings would actually affect ALL applications using SSL. Anyone with any experience please share your comments as they are most appreciated !