~Keiko KiluverakoiJan 10, 2018, 11:05 AM55 PostsMe too...We have just upgraded customer servers to the latest 9.0.1FP9 and are also getting these alerts when testing the SSL config via Qualys Labs. Anyone from IBM care to advise how to mitigate/fix this?
~Keiko KiluverakoiJan 10, 2018, 12:15 PM55 PostsWorkaround...By only enabling ECDHE & DHE cyphers this appears to have worked around the issue and I no longer get the ROBOT errors. FYI this is the notes.ini I used: SSLCipherSpec=C030009FC02F009EC028006BC0140039C0270067C013
~Kelly DesapuladerJan 10, 2018, 3:17 PM15 PostsWork around works for meThanks. This work around worked. My SSLCipherSpec looks like this: SSLCipherSpec=C030009FC028006BC0140039 I only enabled the 256 bit ciphers.
~Anita MinasteringsJan 15, 2018, 11:00 AM90 PostsHere is the list I usedSSLCipherSpec=C030009FC02F009EC028006BC0270067C014 Per SSL Labs that allows support for IE 8-10. Howard
~Vera ZekfoogengonJan 19, 2018, 5:56 PM196 PostsROBOT to be addressed in FP10Daniel Nashed in his blog mentions that ROBOT is to be addressed in Feature Pack 10: http://blog.nashcom.de/nashcomblog.nsf/dx/robot-ssltls-attack.htm Mr. Nashed also makes the point that most browsers would try to use more secure ciphers when they are available, so the actual risk of less secure ciphers may be overstated.