<html><body><div dir="ltr"><font face="ui-sans-serif, sans-serif">
Our UA IdP v 4 on tomcat 8 instances directly support TLS 1.2 connections (SSLLabs “A”). However nearly all clients connect via a load balancer supporting TLS 1.2 and 1.3 (SSLLabs “A+”). Our Shibboleth IdP is also our institutional CAS server used for logins to ERP, and CAS services including back-channel ticket validation requests also worked without a hitch. </font><span style="font-family:ui-sans-serif,sans-serif">I am aware of zero support calls or complaints related to turning off older TLS versions about a year ago.</span></div><div dir="ltr"><font face="ui-sans-serif, sans-serif"><br></font></div><div dir="ltr"><font face="ui-sans-serif, sans-serif">We previously ran IdP v3 on jetty 9; in that environment I edited <font size="2">addExcludeCipherSuites.xml, but follow Scott Cantor’s Jetty SSL settings advice.</font></font></div><div dir="ltr"><font face="ui-sans-serif, sans-serif"><font size="2"><br></font></font></div><div dir="ltr"><font face="ui-sans-serif, sans-serif"><font size="2">David<br></font></font><br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On 30Jun, 2021 at 13:41:33, Brent Goebel <<a href="mailto:Brent.Goebel@du.edu">Brent.Goebel@du.edu</a>> wrote:<br></div>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div>
<div>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
</div>
<div lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal" dir="ltr">...</p>
<p class="MsoNormal">So have you updated your IdP to use TLS 1.2 and above? Did you see any issue with doing so for your IdP for your applications using your IdP for SSO?</p>
<p class="MsoNormal">Which webserver are you running? I’m running Jetty so if you have any insight on how you modified it that would be helpful as well. I started looking around and some say to modify jetty-ssl.xml to ‘ExcludeProtocols’ for 1.0 and 1.1 while
another site said to update jetty-https.xml.</p>
<p class="MsoNormal"><br></p></div></div></div>
</blockquote>
</div>
</div></body></html>