Documentation Index

Fetch the complete documentation index at: https://support.appgate.com/llms.txt

Use this file to discover all available pages before exploring further.

Security specifications

Prev Next

Communications

TLSv1.3 is the default for all communications. When the peer does not support TLSv1.3 then TLSv1.2 will be used as a fallback. The tunnel protocol used for the VPN connection can be configured in Sites > General.

Appliance to Appliance communication

nginx_peer_ciphers = TLS13-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384

Mutual certificate-based authentication with DN checking is used for communications between appliances (port 443)

Client and Admin to Appliance communication (defaults)

nginx_client_ciphers = TLS13-AES256-GCM-SHA384:ECDHE-RSA-AES-256-GCM-SHA384

nginx client on 443 and 8443

SSH to Appliance

Ciphers = AES-256-CTR, AES-192-CTR, AES-128-CTR

Client to Gateway tunnel

Cipher = TLS13-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384

Mutual certificate-based authentication with DN checking is used for communications

Single Packet Authorization

Cipher = AES-256-GCM

Appliance certificate generated by a Controller

SHA512 with RSA, keysize 4096

A Certificate Authority, Maximum number of intermediate CAs: 0, basicConstraints = critical, CA:true, pathlen:0, keyUsage = critical, digitalSignature, cRLSign, keyCertSign

The CA cert is used for the controller-client authentication to communicate with appliances: extendedKeyUsage = clientAuth, serverAuth

Claim and entitlement token encryption

Cipher = AES-256-CTR

Database encryption

Cipher = AES-256-CTR

Backup file

Cipher = GPG symmetric (AES-256-CFB)

Cryptographic Module Validation Program (CMVP) FIPS

6.4.1 and later desktop clients and appliances comply to FIPS 140-3 for to appliance-to-appliance and client-to-appliance communication using the wolfCrypt module. See the certificate.

See FIPS 140-3: Security Requirements for Cryptographic Modules

AppGate updates FIPS compliance as soon as there is a compliant cryptographic module available from wolfCrypt.

6.4.0 desktop clients and appliances comply to FIPS 140-2.

Common Criteria and NIAP Protection Profile (PP)

6.4.2 clients were certified in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme for the Protection Profile for Application Software Version 1.4, with the Functional Package for Transport Layer Security (TLS) Version 1.1 applied.

On May 19, 2026, the 7.0 appliance was filed for Common Criteria evaluation in accordance with the CCEVS process and scheme for the Protection Profile for Application Software Version 2.0, with Functional Package for Transport Layer Security Version 2.1 (TLS-PKG v2.1) and Functional Package for X.509 version 1.0 applied.