

Dataverse uses Windows implementation that is not based on OpenSSL and therefore is not vulnerable.

This is due to known attacks toward OpenSSL implementation.

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 may show up as weak when you performed a SSL report test. Your servers must have the above security protocol to continue running the Dataverse services. Older TLS 1.0 & 1.1 and cipher suites, (for example TLS_RSA) have been deprecated see the announcement. Transport Layer Security (TLS) 1.2 compliance To comply with our security policy for a secure connection, your server must have the following:
