<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Brent,</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We (Oregon State University) removed TLS 1.0 and 1.1 from our IDP earlier this year (slight caveat below).  There were zero issues with SAML because we don't support back-channel (Attribute Query) for SAML.  All of our end-users' browsers were already using
 TLS 1.2.</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We did run into trouble with legacy (old, unsupported) servers making CAS ticket validation requests, a kind of back-channel request.  I cloned off an instance of our IDP, firewalled it down to just those legacy servers, and left it with TLS 1.0 enabled.  I'll
 turn it off once the legacy hosts have been retired (which is in progress already).</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Do you have any back-channel services?  Have you turned on protocol logging to see which hosts, if any, are using TLS 1.0 or 1.1?</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Andy</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Brent Goebel <Brent.Goebel@du.edu><br>
<b>Sent:</b> Wednesday, June 30, 2021 2:41 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: RE: InCommon Baseline TLS 1.2</font>
<div> </div>
</div>
<div lang="EN-US">
<p><span style="color:#D73F09">[This email originated from outside of OSU. Use caution with links and attachments.]</span></p>
<div>
<div class="x_WordSection1">
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
David, </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Thanks for the feedback. The SSLLabs grading had my cipher suites at a grade level of an ¡®A.¡¯ I understand other areas play a part in the grading, but the TLS is one that stuck out the most. My guess is I won¡¯t score an A until I address that one in addition
 to any other areas noted as lower than an A with their scoring. </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
So have you updated your IdP to use TLS 1.2 and above? Did you see any issue with doing so for your IdP for your applications using your IdP for SSO?
</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Which webserver are you running? I¡¯m running Jetty so if you have any insight on how you modified it that would be helpful as well. I started looking around and some say to modify jetty-ssl.xml to ¡®ExcludeProtocols¡¯ for 1.0 and 1.1 while another site said to
 update  jetty-https.xml.</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Thanks again for your feedback and help.</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Best,</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Brent</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<div>
<div style="border:none; border-top:solid #E1E1E1 1.0pt; padding:3.0pt 0in 0in 0in">
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
<b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of </b>IAM David Bantz<br>
<b>Sent:</b> Wednesday, June 30, 2021 3:32 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> [EXTERNAL] RE: InCommon Baseline TLS 1.2</p>
</div>
</div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<div>
<table class="x_MsoNormalTable" cellspacing="0" cellpadding="0" border="0" align="left">
<tbody>
<tr>
<td style="width:100.0%; background:#FFDF00; padding:0in 0in 0in 0in" width="100%">
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;text-align:center" align="center">
[External Email From]: <b><span style="color:black"><a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a></span></b></p>
</td>
</tr>
</tbody>
</table>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;margin-bottom:12.0pt">
 </p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
TLS 1.0 (1999) and TLS 1.1 (2006) are formally deprecated by IETF RFC 8996. </p>
</div>
<div>
<div style="border:solid #CCCCCC 1.0pt; padding:8.0pt 8.0pt 8.0pt 8.0pt; background:#FFFDF5">
<pre style="margin: 0in 0in 0.0001pt; font-size: 10pt; font-family: "Courier New";margin-bottom:7.9pt; background:#FFFDF5; word-break:break-all; border:none; padding:0in; box-sizing:border-box; border-top-left-radius:4px; border-top-right-radius:4px; border-bottom-right-radius:4px; border-bottom-left-radius:4px; font-variant-ligatures:normal; overflow:auto"><span style="font-size:10.5pt; color:black">These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008...</span><span style="font-size:10.5pt"></span></pre>
</div>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Web sites that negotiate a TLS 1.0 or 1.1 protocol will trigger user warnings that connections are ¡°not secure¡± from Chrome and other browsers.</p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
IMO Yes, you really should regard those older protocols as a security risk and update to support TLS 1.2 or 1.3. There are some niche needs for the older protocols to support legacy devices that cannot support newer secure TLS, but you can support legacy clients
 such as IE 11 and Android 5 using TLS 1.2.</p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Note that the SSLLabs grading is not directly translatable into support for TLS versions. You can disable support for anything less than TLS 1.2 and still get a ¡°grade¡± of B from SSLLabs if the server negotiates weak cipher suites. </p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
David St. Pierre Bantz</p>
</div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
On 30Jun, 2021 at 12:11:44, Brent Goebel <<a href="mailto:Brent.Goebel@du.edu">Brent.Goebel@du.edu</a>> wrote:</p>
</div>
<blockquote style="border:none; border-left:solid #CCCCCC 1.0pt; padding:0in 0in 0in 6.0pt; margin-left:4.8pt; margin-right:0in">
<div>
<div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Hello all, </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
I¡¯m following the InCommon Baseline Expectations 2 that is required for our IdPs. I see that one of the requirements is related to encryption. Link here:
<a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.com%2Fv3%2F__https%3A%2Fspaces.at.internet2.edu%2Fdisplay%2Ffederation%2Fbe2-guide-encrypt-endpoints__%3B!!NCZxaNi9jForCP_SxBKJCA!HSPx7AFH-vR_C-tv_jAP6QOcC4Fdu0En_G5YRrLa1wk2xhO_j9e5Mk0bcpIygh3YOQ%24&data=04%7C01%7C%7Cc2bbe9a2bda84800c77108d93c0fda36%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C637606861054717428%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=9ImkoJAUxxRwOtwO2nB2Acn2cfOcJ%2FGNmvJcpEu2hWA%3D&reserved=0" originalsrc="https://urldefense.com/v3/__https:/spaces.at.internet2.edu/display/federation/be2-guide-encrypt-endpoints__;!!NCZxaNi9jForCP_SxBKJCA!HSPx7AFH-vR_C-tv_jAP6QOcC4Fdu0En_G5YRrLa1wk2xhO_j9e5Mk0bcpIygh3YOQ$" shash="i/zmNZ1CVE2Fpg+V4B5DAyXfePL5JQVuz17Q9RiwQMrDLKNXlPA7hdBh1YpnsYMX7oRqw4sIG/YPcYNtEsw6IiCJ+q4UMnug1anETpyck8JwK6F1vDvAuqqbg0JAU0lh0bvAh1OKJNQsHzyJvKit8E0U+Xt0QiVLkmGLwC9o1tY=">
https://spaces.at.internet2.edu/display/federation/be2-guide-encrypt-endpoints</a></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
When I run the SSLLab Server Test on our IdP domain I get a score of a B. They require a score of an A or higher. I am getting a B because we support TLS 1.1. It seems like in order to get a higher score I need to not support TLS 1.0 and 1.1 and start supporting
 TLS 1.2. </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Looking through the Shibboleth user group I saw one conversation where some participants did not agree with InCommon on this requirement (attached). That was back in March 2021 so I wanted to start a new conversation on this.
</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
What are your thoughts or plans with this? I wanted to reach out and see what everyone is doing in regards to this. Are you all moving to TLS 1.2 to score an ¡®A¡¯? Or are you just staying at a score of a ¡®B¡¯ for this and moving on? Any concerns you have with
 moving an IdP from TLS 1.0/1.1 to TLS 1.2?  </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
InCommon wants this all done by mid-July so I¡¯m thinking some of you already started this.
</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Thanks,</p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
Brent </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;background:white">
<b><span style="font-size:13.0pt; font-family:"Times New Roman",serif; color:#201F1E">Brent Goebel</span></b></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;background:white">
<span style="font-family:"Times New Roman",serif; color:#201F1E">Systems Engineer III</span></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;background:white">
<span style="font-family:"Times New Roman",serif; color:#201F1E">Information Technology </span><span style="color:#830033">¡¬</span><span style="font-family:"Times New Roman",serif; color:#1F497D"> </span><span style="font-family:"Times New Roman",serif; color:#201F1E"> University
 of Denver</span></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;background:white">
<span style="font-family:"Times New Roman",serif; color:#201F1E">2100 </span><span style="font-family:"Times New Roman",serif; color:black">South High Street </span><span style="color:#830033">¡¬</span><span style="font-family:"Times New Roman",serif; color:#1F497D"> </span><span style="font-family:"Times New Roman",serif; color:black">Denver
 CO 80210</span></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;background:white">
<span style="font-family:"Times New Roman",serif; color:#201F1E"><a href="mailto:brent.goebel@du.edu">brent.goebel@du.edu</a></span></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;background:white">
<span style="color:#201F1E"> </span></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
<img id="x_Picture_x0020_1" alt="DULogo_IT" style="width:2.6354in; height:.875in" width="253" height="84" border="0" data-outlook-trace="F:1|T:1" src="cid:image001.jpg@01D76DC6.50CB1E40"></p>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
 </p>
</div>
</div>
</div>
<div>
<div>
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: "Calibri", sans-serif;">
-- <br>
For Consortium Member technical support, see <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.com%2Fv3%2F__https%3A%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg__%3B!!NCZxaNi9jForCP_SxBKJCA!HSPx7AFH-vR_C-tv_jAP6QOcC4Fdu0En_G5YRrLa1wk2xhO_j9e5Mk0bcpIq3YS0Rw%24&data=04%7C01%7C%7Cc2bbe9a2bda84800c77108d93c0fda36%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C637606861054727425%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=szpA3Pdx25T9YdiQE9t6q%2BDTrZdLivdSLFWAWoY2Z8s%3D&reserved=0" originalsrc="https://urldefense.com/v3/__https:/wiki.shibboleth.net/confluence/x/coFAAg__;!!NCZxaNi9jForCP_SxBKJCA!HSPx7AFH-vR_C-tv_jAP6QOcC4Fdu0En_G5YRrLa1wk2xhO_j9e5Mk0bcpIq3YS0Rw$" shash="iE0qW+m9EXX4Nr2B2oaZMpwtGpdGQOaTt/Yp+DNLMNNfSHFLLXqIZ3Rg+K9FaeOlfvqSWsjjEFgTzNt2omvDXtmrTjlYqX+6RKhS3OLiGiVADIfMrIKxA3eHfr2BoEcsPV0DtYlWNlW9FtaeSFo9NZL4ZRpcgOX7H+sX9eJ8cPU=">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></p>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>