As part of ongoing Salesforce security hardening efforts, Anypoint MQ endpoints were updated to comply with current Salesforce security standards and modern TLS best practices.
This hardening includes:
Supporting only AEAD cipher suites such as:
GCM
As a result, legacy cipher suites are no longer accepted, including:
CBC-SHA ciphers
Static-RSA cipher suites
These legacy ciphers had already been deprecated in underlying TLS libraries and are now fully disabled on Anypoint MQ endpoints.
Impact:
External applications using older TLS configurations or legacy cipher suites may fail to establish SSL/TLS connections to Anypoint MQ endpoints.
Typical symptoms include:
- SSL handshake failures
- Inability to publish or consume MQ messages
Customers should update their applications or TLS libraries to use modern supported cipher suites.
Recommended cipher suites include:
005321986

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.