<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:dt="uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}
span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">David, <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks for the feedback. The SSLLabs grading had my cipher suites at a grade level of an ‘A.’ I understand other areas play a part in the grading, but the TLS is one that stuck out the most. My guess is I won’t score an A until I address
 that one in addition to any other areas noted as lower than an A with their scoring.
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">So have you updated your IdP to use TLS 1.2 and above? Did you see any issue with doing so for your IdP for your applications using your IdP for SSO?
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Which webserver are you running? I’m running Jetty so if you have any insight on how you modified it that would be helpful as well. I started looking around and some say to modify jetty-ssl.xml to ‘ExcludeProtocols’ for 1.0 and 1.1 while
 another site said to update  jetty-https.xml.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks again for your feedback and help.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Best,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Brent<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>IAM David Bantz<br>
<b>Sent:</b> Wednesday, June 30, 2021 3:32 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> [EXTERNAL] RE: InCommon Baseline TLS 1.2<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" align="left">
<tbody>
<tr>
<td width="100%" style="width:100.0%;background:#FFDF00;padding:0in 0in 0in 0in">
<p class="MsoNormal" align="center" style="text-align:center;mso-element:frame;mso-element-frame-hspace:2.25pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:column;mso-height-rule:exactly">
[External Email From]: <b><span style="color:black"><a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a></span></b><o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">TLS 1.0 (1999) and TLS 1.1 (2006) are formally deprecated by IETF RFC 8996. <o:p></o:p></p>
</div>
<div>
<div style="mso-element:para-border-div;border:solid #CCCCCC 1.0pt;padding:8.0pt 8.0pt 8.0pt 8.0pt;background:#FFFDF5">
<pre style="margin-bottom:7.9pt;background:#FFFDF5;word-break:break-all;border:none;padding:0in;box-sizing:border-box;border-top-left-radius:4px;border-top-right-radius:4px;border-bottom-right-radius:4px;border-bottom-left-radius:4px;font-variant-ligatures:normal;overflow:auto"><span style="font-size:10.5pt;color:black">These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008...</span><span style="font-size:10.5pt"><o:p></o:p></span></pre>
</div>
</div>
<div>
<p class="MsoNormal">Web sites that negotiate a TLS 1.0 or 1.1 protocol will trigger user warnings that connections are “not secure” from Chrome and other browsers.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">IMO Yes, you really should regard those older protocols as a security risk and update to support TLS 1.2 or 1.3. There are some niche needs for the older protocols to support legacy devices that cannot support newer secure TLS, but you
 can support legacy clients such as IE 11 and Android 5 using TLS 1.2.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Note that the SSLLabs grading is not directly translatable into support for TLS versions. You can disable support for anything less than TLS 1.2 and still get a “grade” of B from SSLLabs if the server negotiates weak cipher suites. <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">David St. Pierre Bantz<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="MsoNormal">On 30Jun, 2021 at 12:11:44, Brent Goebel <<a href="mailto:Brent.Goebel@du.edu">Brent.Goebel@du.edu</a>> wrote:<o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Hello all,
<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">I’m following the InCommon Baseline Expectations 2 that is required for our IdPs. I see that one of the requirements is related to encryption. Link here:
<a href="https://urldefense.com/v3/__https:/spaces.at.internet2.edu/display/federation/be2-guide-encrypt-endpoints__;!!NCZxaNi9jForCP_SxBKJCA!HSPx7AFH-vR_C-tv_jAP6QOcC4Fdu0En_G5YRrLa1wk2xhO_j9e5Mk0bcpIygh3YOQ$">
https://spaces.at.internet2.edu/display/federation/be2-guide-encrypt-endpoints</a><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">When I run the SSLLab Server Test on our IdP domain I get a score of a B. They require a score of an A or higher. I am getting a B because we support TLS 1.1. It seems like in order
 to get a higher score I need to not support TLS 1.0 and 1.1 and start supporting TLS 1.2.
<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Looking through the Shibboleth user group I saw one conversation where some participants did not agree with InCommon on this requirement (attached). That was back in March 2021
 so I wanted to start a new conversation on this. <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">What are your thoughts or plans with this? I wanted to reach out and see what everyone is doing in regards to this. Are you all moving to TLS 1.2 to score an ‘A’? Or are you just
 staying at a score of a ‘B’ for this and moving on? Any concerns you have with moving an IdP from TLS 1.0/1.1 to TLS 1.2?  <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">InCommon wants this all done by mid-July so I’m thinking some of you already started this.
<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Thanks,<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Brent
<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;background:white">
<b><span style="font-size:13.0pt;font-family:"Times New Roman",serif;color:#201F1E">Brent Goebel</span></b><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;background:white">
<span style="font-family:"Times New Roman",serif;color:#201F1E">Systems Engineer III</span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;background:white">
<span style="font-family:"Times New Roman",serif;color:#201F1E">Information Technology </span><span style="color:#830033">‖</span><span style="font-family:"Times New Roman",serif;color:#1F497D"> </span><span style="font-family:"Times New Roman",serif;color:#201F1E"> University
 of Denver</span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;background:white">
<span style="font-family:"Times New Roman",serif;color:#201F1E">2100 </span><span style="font-family:"Times New Roman",serif;color:black">South High Street </span><span style="color:#830033">‖</span><span style="font-family:"Times New Roman",serif;color:#1F497D"> </span><span style="font-family:"Times New Roman",serif;color:black">Denver
 CO 80210</span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;background:white">
<span style="font-family:"Times New Roman",serif;color:#201F1E"><a href="mailto:brent.goebel@du.edu">brent.goebel@du.edu</a></span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;background:white">
<span style="color:#201F1E"> </span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><img border="0" width="253" height="84" style="width:2.6354in;height:.875in" id="Picture_x0020_1" src="cid:image001.jpg@01D76DC6.50CB1E40" alt="DULogo_IT"><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
</div>
</div>
</div>
<div>
<div>
<p class="MsoNormal">-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https:/wiki.shibboleth.net/confluence/x/coFAAg__;!!NCZxaNi9jForCP_SxBKJCA!HSPx7AFH-vR_C-tv_jAP6QOcC4Fdu0En_G5YRrLa1wk2xhO_j9e5Mk0bcpIq3YS0Rw$">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</body>
</html>