Hi everyone,
To further strengthen the security of Zoho WorkDrive, we’re updating the TLS cipher suites supported across our services. As part of this change, older and less secure cipher suites are being phased out.
If your browser, API client, desktop application, or custom integration uses outdated TLS configurations, you may experience connectivity issues once enforcement is complete. We recommend reviewing your environment and updating it at the earliest.
Supported TLS cipher suites
Zoho WorkDrive supports only the following secure TLS 1.2 and TLS 1.3 cipher suites. Ensure that your browsers, API clients, and integrations are configured to use one of the supported cipher suites listed below:
TLS 1.2
- ECDHE_RSA with AES-GCM or CHACHA20-POLY1305
- ECDHE_ECDSA with AES-GCM or CHACHA20-POLY1305
TLS 1.3
- TLS_AES_128_GCM_SHA256
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256
Verify your configuration
Response codes:
- 200 OK: Strong cipher in use. Your configuration is compatible.
- 400 Bad Request: Your application is using an unsupported cipher suite and requires an update.
Who should review this?
This update is particularly important if you use:
- WorkDrive APIs
- Custom applications or integrations
- SDKs or automation scripts
- Older desktop applications or runtime environments
Users accessing WorkDrive through modern, up-to-date web browsers typically won’t need to take any action.
What should you do?
If your environment is using unsupported TLS cipher suites, update your browser, operating system, runtime, TLS libraries, or client application to a version that supports the recommended TLS 1.2 or TLS 1.3 cipher suites. Keeping these components up to date will help ensure uninterrupted connectivity to Zoho WorkDrive.
Need help?
Thank you for helping us keep Zoho WorkDrive secure.