Jump to content

Recommended Posts

Posted

Just going through GP and see we still have SSL 3.0 enabled. Am I right in thinking SSL 3.0 is deprecated and should be disabled and the only protocols that should be enabled is TLS 1.2?

 

Thanks

Posted
Just going through GP and see we still have SSL 3.0 enabled. Am I right in thinking SSL 3.0 is deprecated and should be disabled and the only protocols that should be enabled is TLS 1.2?

 

Thanks

 

Yes, but you'd want to test carefully that some legacy software you depend on isn't tied to this before you turn anything off.

  • Thanks 1
Posted
Yes, but you'd want to test carefully that some legacy software you depend on isn't tied to this before you turn anything off.

Yep, when we turned legacy TLS versions off our Inventry system stopped working.

Posted
Yep, when we turned legacy TLS versions off our Inventry system stopped working.

 

I have already found that access to our Orbtalk VoIP portal stopped working when I turned off TLS 1.0.

Posted

A RDS deployment without a dedicated SQL instance will use WID. This only supports TLS 1.0.

 

Enable schannel logging before making any changes.

  • 3 months later...
Posted
Has anyone enabled TLS1.3 for M365? Is there any reason not too given it is reported as a quicker in the handshake operation and it's ciphers are regarded as more secure?
Posted
Has anyone enabled TLS1.3 for M365? Is there any reason not too given it is reported as a quicker in the handshake operation and it's ciphers are regarded as more secure?

 

how do we turn this on i've just tried googeling it as in MyNCSC its a little ! against my o365 mailcheck.... and i cant find the answer

Posted
Having dug deeper, all I can find is that Windows Server can be made to use 1.3, but options like scripts or regedits. For Office 365, this link talks about 1.3, but rather vaguely it states "TLS version 1.3 (TLS 1.3) is supported by some of the services.". So for now, can't see a way to enforce 1.3 - which given it release 4 years ago, not great, but 1.2 is regarded as fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...