Knowledge Base

Finding

C

Encryption Algorithm: Rivest Cipher 2 (RC2)

Summary

Security

Encryption algorithm Rivest Cipher 2[362][363] is a block cipher[78][79][80][81] which is theoretically weakened against vulnerabilities[368][369] (eg: related-key attack[68], chosen-plaintext attack[56]).

Suggestion

Remove the cipher suite from the list of cipher suites supported by your server.

Evaluate your host!

Type a URL to analyze a service

Get a prompt and clear overview of your security configuration. Right now!

Config Snippets

You can fix your security setting with the following config snippets in various services. You simply copy-paste (or delete) them to get a better secirity and grade. Do not forget to re-check your modified settings above.

If you want to reveal your security weaknesses and monitor your services or supply chain sign up for our beta test.

i
NGINX
OpenSSL version: 0.9.8+
ssl_ciphers …:!RC2
i
Apache
OpenSSL version: 0.9.8+
SSLCipherSuite …:!RC2

Affected Cipher Suites

Cipher suite name
TLS_RSA_WITH_RC2_CBC_MD5