TLS 1.3 Support
TLS 1.3 Experimental Support may be enabled in all editions.
Date Entered: 07/10/2017 Last Updated: 12/06/2017
All editions of IPWorks include experimental support for TLS 1.3. This is available in both client and server side components and can be enabled by setting SSLEnabledProtocols. For instance:
component.Config("SSLEnabledProtocols=12288"); //TLS 1.3
When enabled the component will automatically set UseInternalSecurityAPI to True and will not rely on any system libraries. Support for TLS 1.3 is still experimental and additional algorithms and cipher support will be added in the future. TLS13SignatureAlgorithms, TLS13SupportedGroups, and TLS13KeyShareGroups settings control the supported signature algorithms and key exchange groups respectively.
The following SSLEnabledCipherSuites are supported and enabled by default:
The following TLS13SignatureAlgorithms are supported and enabled by default:
The TLS13SupportedGroups controls the supported key exchange groups available for use with (EC)DHE during the key exchange. This list should not be modified in most cases. The following values are supported by default:
- ecdhe_secp256r1 (default)
- ecdhe_secp384r1 (default)
- ffdhe_2048 (default)
- ffdhe_3072 (default)
Additional features and supported platforms are coming soon.
We appreciate your feedback. If you have any questions, comments, or suggestions about this entry please contact our support team at firstname.lastname@example.org.