Effective 29.09.2026, we will be retiring support for a list of old cipher suites which are considered legacy and no longer meet modern security standards. This is a breaking change for any client, API connection, or integration that relies exclusively on these specific deprecated ciphers for connectivity.
To ensure uninterrupted service and maintain connection stability after the deprecation date, we recommend you to check what ciphers are currently used by your service. You can find the list of ciphers we will retire from below.
If the only ciphers listed in your service are on our deprecation list - the service will fail to connect once we turn the weaker ciphers off. In that case, your technical or security team must update any connecting clients (including API calls, system integrations, and client browsers) to utilize modern, forward secrecy-enabled cipher suites.
Our staging environment already does not accept the ciphers on our deprecation list. So if you have a testing environment that is connected to staging - that is a good indicator that things will continue to work in production .
The following ciphers will be completely removed from our supported list on 29.09.2026:
Cipher Suite |
DHE-RSA-AES128-GCM-SHA256 |
DHE-RSA-AES256-GCM-SHA384 |
DHE-DSS-AES128-GCM-SHA256 |
DHE-RSA-CHACHA20-POLY1305 |
kEDH+AESGCM |
ECDHE-RSA-AES128-SHA256 |
ECDHE-ECDSA-AES128-SHA256 |
ECDHE-RSA-AES256-SHA384 |
ECDHE-ECDSA-AES256-SHA384 |
DHE-RSA-AES128-SHA256 |
DHE-RSA-AES128-SHA |
DHE-DSS-AES128-SHA256 |
DHE-RSA-AES256-SHA256 |
DHE-DSS-AES256-SHA |
DHE-RSA-AES256-SHA |
Please review this information and coordinate with your technical team to ensure your systems are not using outdated ciphers.
If you have any questions or require assistance with testing your connectivity, contact our support team at partners.sign@visma.com.
Thank you for your partnership as we continue to enhance the security of our platform.
Sincerely,
The Visma Sign team