User Manual

Table Of Contents
SARA-R4 series-AT commands manual
UBX-17003787 - R16
20Device and data security
Page 242 of 401
SARA-R410M-63B / SARA-R410M-73B / SARA-R410M-83B
When using a TCP socket, if <op_code>=1 (SSL/TLS version) and <param_val>=0 (any version) the
connection is allowed only to TLS/SSL servers (version TLSv1.2) which support at least one of the
following default cipher suites:
o (0xc02b) TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
o (0xc02f) TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
o (0xc02c) TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
o (0xc030) TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
o (0xc023) TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
o (0xc027) TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
o (0xc024) TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
o (0xc028) TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
o (0x003c) TLS_RSA_WITH_AES_128_CBC_SHA256
o (0x003d) TLS_RSA_WITH_AES_256_CBC_SHA256
o (0x0067) TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
o (0x006b) TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
o (0x008c) TLS_PSK_WITH_AES_128_CBC_SHA
o (0x0091) TLS_DHE_PSK_WITH_AES_256_CBC_SHA
o (0x008d) TLS_PSK_WITH_AES_256_CBC_SHA
When using an UDP socket, if <op_code>=1 (DTLS version) and <param_val>=0 (any version) the
connection is allowed only to DTLS servers (version DTLSv1.2) which support the following default cipher
suites:
o (0xc0a8) TLS_PSK_WITH_AES_128_CCM_8
SARA-R410M-02B / SARA-R410M-52B / SARA-R412M / SARA-N4
If <op_code>=1 (SSL/TLS version) and <param_val>=0 (any version) the connection is allowed only to TLS/
SSL servers which support at least one of the following default cipher suites:
o (0x002f) TLS_RSA_WITH_AES_128_CBC_SHA
o (0x003C) TLS_RSA_WITH_AES_128_CBC_SHA256
o (0x0035) TLS_RSA_WITH_AES_256_CBC_SHA
o (0x003D) TLS_RSA_WITH_AES_256_CBC_SHA256
o (0x000a) TLS_RSA_WITH_3DES_EDE_CBC_SHA
o (0x008c) TLS_PSK_WITH_AES_128_CBC_SHA
o (0x008d) TLS_PSK_WITH_AES_256_CBC_SHA
o (0x008b) TLS_PSK_WITH_3DES_EDE_CBC_SHA
o (0x0094) TLS_RSA_PSK_WITH_AES_128_CBC_SHA
o (0x0095) TLS_RSA_PSK_WITH_AES_256_CBC_SHA
o (0x0093) TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA
o (0x00ae) TLS_PSK_WITH_AES_128_CBC_SHA256
o (0x00af) TLS_PSK_WITH_AES_256_CBC_SHA384
o (0x00b6) TLS_RSA_PSK_WITH_AES_128_CBC_SHA256
o (0x00b7) TLS_RSA_PSK_WITH_AES_256_CBC_SHA384
<param_val>=99 (cipher suite selection using IANA enumeration) is not supported.
SARA-R410M-01B
<param_val>=99 (cipher suite selection using IANA enumeration) is not supported.
The unique certificate validation level (<op_code>=0) supported is the level 0 (no validation, <param_
val>=0).
The unique minimum SSL/TLS version (<op_code>=1) supported is <param_val>=0 (the server can use
any version for the connection).
If <op_code>=1 (SSL/TLS/DTLS version) and <param_val>=0 (any version) the connection is allowed only
to TLS/SSL servers which support at least one of the following default cipher suites:
o (0x002f) TLS_RSA_WITH_AES_128_CBC_SHA
o (0x003C) TLS_RSA_WITH_AES_128_CBC_SHA256
o (0x0035) TLS_RSA_WITH_AES_256_CBC_SHA