Certificate Enrollment Gateway supports the following TLS configuration.

TLS versions

Key Encapsulation Mechanisms (KEMs)

​1.2 and 1.3

​X25519MLKEM768  

See below for the supported ciphersuites.

Ciphersuite

TSL 1.2

TLS 1.3

ECDHE-ECDSA-AES256-GCM-SHA384

(tick) 

(tick) 

ECDHE-RSA-AES256-GCM-SHA384

(tick) 

(tick) 

​ECDHE-RSA-CHACHA20-POLY1305

(tick) 

 ​

TLS_AES_128_GCM_SHA256


(tick) 

TLS_CHACHA20_POLY1305_SHA256


(tick)