From 70d483ef59a773850d4c9865bb175155aacd954f Mon Sep 17 00:00:00 2001 From: Olufunke Moronfolu Date: Fri, 9 Oct 2026 10:28:47 +0200 Subject: [PATCH 1/2] ECDSA cipher suite & RSA certificate support in Mendix Cloud TLS config --- .../en/docs/releasenotes/deployment/mendix-cloud/2025.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md b/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md index 8dcef15e714..32b98728719 100644 --- a/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md +++ b/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md @@ -117,6 +117,14 @@ We will also introduce new, recommended SSL/TLS ciphers. These additions will fi * `TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256` * `TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256` +**ECDSA cipher suites and certificates** + +The `TLS_ECDHE_ECDSA_*` cipher suites are enabled in the Mendix Cloud Transport Layer Security (TLS) configuration. However, a server can only negotiate them when it presents an Elliptic Curve Digital Signature Algorithm (ECDSA) certificate. + +Mendix Cloud currently supports only RSA certificates. The default `*.mendixcloud.com` domains use an RSA certificate, and you can only upload RSA certificates for custom domains. + +As a result, the `TLS_ECDHE_ECDSA_*` cipher suites cannot be used yet. With an RSA certificate, the TLS 1.2 cipher suites that work are the `TLS_ECDHE_RSA_*` suites, such as `TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256` and `TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384`. + ## September 2025 ### September 21, 2025 From 624726b426d8c372444b42c16f63589fc8333c4a Mon Sep 17 00:00:00 2001 From: Olufunke Moronfolu Date: Fri, 9 Oct 2026 11:59:16 +0200 Subject: [PATCH 2/2] Update TLS cipher suite and certificate support info --- .../docs/deployment/mendix-cloud-deploy/custom-domains.md | 6 ++++++ .../en/docs/releasenotes/deployment/mendix-cloud/2025.md | 8 +------- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/content/en/docs/deployment/mendix-cloud-deploy/custom-domains.md b/content/en/docs/deployment/mendix-cloud-deploy/custom-domains.md index d655a2e8ecb..34e1d073bee 100644 --- a/content/en/docs/deployment/mendix-cloud-deploy/custom-domains.md +++ b/content/en/docs/deployment/mendix-cloud-deploy/custom-domains.md @@ -100,6 +100,12 @@ For application-level certificates, you need to [upload](/developerportal/deploy For central certificates, a single certificate managed by the Mendix Admin can be reused across multiple custom domains and applications, if applicable. +### Which Certificates and TLS Cipher Suites Does Mendix Cloud Support? {#supported-certificates} + +Mendix Cloud currently supports only RSA certificates. The default `*.mendixcloud.com` domains use an RSA certificate, and you can only upload RSA certificates for custom domains. The `TLS_ECDHE_ECDSA_*` cipher suites are enabled in the Mendix Cloud Transport Layer Security (TLS) configuration. However, a server can only negotiate them when it presents an Elliptic Curve Digital Signature Algorithm (ECDSA) certificate. As a result, these cipher suites cannot be used yet. + +With an RSA certificate, the TLS 1.2 cipher suites that work are the `TLS_ECDHE_RSA_*` suites, such as `TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256` and `TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384`. + ## Read More * [Certificate Management](/control-center/certificate-management/) diff --git a/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md b/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md index 32b98728719..266d31a5f1f 100644 --- a/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md +++ b/content/en/docs/releasenotes/deployment/mendix-cloud/2025.md @@ -117,13 +117,7 @@ We will also introduce new, recommended SSL/TLS ciphers. These additions will fi * `TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256` * `TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256` -**ECDSA cipher suites and certificates** - -The `TLS_ECDHE_ECDSA_*` cipher suites are enabled in the Mendix Cloud Transport Layer Security (TLS) configuration. However, a server can only negotiate them when it presents an Elliptic Curve Digital Signature Algorithm (ECDSA) certificate. - -Mendix Cloud currently supports only RSA certificates. The default `*.mendixcloud.com` domains use an RSA certificate, and you can only upload RSA certificates for custom domains. - -As a result, the `TLS_ECDHE_ECDSA_*` cipher suites cannot be used yet. With an RSA certificate, the TLS 1.2 cipher suites that work are the `TLS_ECDHE_RSA_*` suites, such as `TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256` and `TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384`. +The `TLS_ECDHE_ECDSA_*` cipher suites require an ECDSA certificate, which Mendix Cloud doesn't currently support. For details, refer to the [Which Certificates and TLS Cipher Suites Does Mendix Cloud Support?](/developerportal/deploy/custom-domains/#supported-certificates) section in *Custom Domains*. ## September 2025