Note the following changes to the DEFAULT cipher list.
Oracle recommends the following ciphers, and includes them in the DEFAULT cipher list:
The following ciphers have been added and included in the DEFAULT cipher list in CZ810m1p6:
Oracle supports the following ciphers, but does not include them in the DEFAULT cipher list:
Oracle supports the following ciphers for debugging purposes only:
- TLS_RSA_WITH_NULL_SHA256 (debug only)
- TLS_RSA_WITH_NULL_SHA (debug only)
- TLS_RSA_WITH_NULL_MD5 (debug only)
Oracle supports the following ciphers, but considers them not secure. They are not included in the DEFAULT cipher-list, but they are included when you set the cipher-list attribute to ALL. Note that they trigger verify-config error messages.
To configure TLS ciphers, use the cipher-list attribute in the tls-profile configuration element.
WARNING:When you set tls-version to either tlsv1 or tlsv11 and you want to use ciphers that Oracle considers not secure, you must manually add them to the cipher-list attribute.