Jobos Posted August 23, 2022 Posted August 23, 2022 Just going through GP and see we still have SSL 3.0 enabled. Am I right in thinking SSL 3.0 is deprecated and should be disabled and the only protocols that should be enabled is TLS 1.2? Thanks
Roberto Posted August 23, 2022 Posted August 23, 2022 Just going through GP and see we still have SSL 3.0 enabled. Am I right in thinking SSL 3.0 is deprecated and should be disabled and the only protocols that should be enabled is TLS 1.2? Thanks Yes, but you'd want to test carefully that some legacy software you depend on isn't tied to this before you turn anything off. 1
RLR Posted August 24, 2022 Posted August 24, 2022 Yes, but you'd want to test carefully that some legacy software you depend on isn't tied to this before you turn anything off. Yep, when we turned legacy TLS versions off our Inventry system stopped working.
Jobos Posted August 24, 2022 Author Posted August 24, 2022 Yep, when we turned legacy TLS versions off our Inventry system stopped working. I have already found that access to our Orbtalk VoIP portal stopped working when I turned off TLS 1.0.
free780 Posted August 24, 2022 Posted August 24, 2022 A RDS deployment without a dedicated SQL instance will use WID. This only supports TLS 1.0. Enable schannel logging before making any changes.
Ditto Posted December 9, 2022 Posted December 9, 2022 Has anyone enabled TLS1.3 for M365? Is there any reason not too given it is reported as a quicker in the handshake operation and it's ciphers are regarded as more secure?
k-strider Posted December 9, 2022 Posted December 9, 2022 Has anyone enabled TLS1.3 for M365? Is there any reason not too given it is reported as a quicker in the handshake operation and it's ciphers are regarded as more secure? how do we turn this on i've just tried googeling it as in MyNCSC its a little ! against my o365 mailcheck.... and i cant find the answer
Ditto Posted December 9, 2022 Posted December 9, 2022 I'll have to check but I thought I had read it was possible within exchange admin center.
Ditto Posted December 11, 2022 Posted December 11, 2022 Having dug deeper, all I can find is that Windows Server can be made to use 1.3, but options like scripts or regedits. For Office 365, this link talks about 1.3, but rather vaguely it states "TLS version 1.3 (TLS 1.3) is supported by some of the services.". So for now, can't see a way to enforce 1.3 - which given it release 4 years ago, not great, but 1.2 is regarded as fine.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now