<html><body><div dir="ltr">TLS 1.0 (1999) and TLS 1.1 (2006) are formally deprecated by IETF RFC 8996. </div><div dir="ltr"><pre style="box-sizing:border-box;overflow:auto;font-family:"PT Mono",Monaco,monospace;font-size:14px;padding:10px;margin-top:0px;margin-bottom:10.5px;line-height:1.214;word-break:break-all;background-color:rgb(255,253,245);border:1px solid rgb(204,204,204);border-top-left-radius:4px;border-top-right-radius:4px;border-bottom-right-radius:4px;border-bottom-left-radius:4px;font-variant-ligatures:normal">These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008...</pre></div><div dir="ltr">Web sites that negotiate a TLS 1.0 or 1.1 protocol will trigger user warnings that connections are “not secure” from Chrome and other browsers.</div><div dir="ltr"><br></div><div dir="ltr">IMO Yes, you really should regard those older protocols as a security risk and update to support TLS 1.2 or 1.3. There are some niche needs for the older protocols to support legacy devices that cannot support newer secure TLS, but you can support legacy clients such as IE 11 and Android 5 using TLS 1.2.</div><div dir="ltr"><br></div><div dir="ltr">Note that the SSLLabs grading is not directly translatable into support for TLS versions. You can disable support for anything less than TLS 1.2 and still get a “grade” of B from SSLLabs if the server negotiates weak cipher suites. </div><div dir="ltr"><br></div><div dir="ltr">David St. Pierre Bantz</div><div dir="ltr"><br>
    <div class="gmail_quote">
        <div dir="ltr" class="gmail_attr">On 30Jun, 2021 at 12:11:44, Brent Goebel <<a href="mailto:Brent.Goebel@du.edu">Brent.Goebel@du.edu</a>> wrote:<br></div>
        <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
            <div>
<div>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">

</div>
<div lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hello all, </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">I’m following the InCommon Baseline Expectations 2 that is required for our IdPs. I see that one of the requirements is related to encryption. Link here:
<a href="https://spaces.at.internet2.edu/display/federation/be2-guide-encrypt-endpoints">
https://spaces.at.internet2.edu/display/federation/be2-guide-encrypt-endpoints</a></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">When I run the SSLLab Server Test on our IdP domain I get a score of a B. They require a score of an A or higher. I am getting a B because we support TLS 1.1. It seems like in order to get a higher score I need to not support TLS 1.0 and
 1.1 and start supporting TLS 1.2. </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Looking through the Shibboleth user group I saw one conversation where some participants did not agree with InCommon on this requirement (attached). That was back in March 2021 so I wanted to start a new conversation on this.
</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">What are your thoughts or plans with this? I wanted to reach out and see what everyone is doing in regards to this. Are you all moving to TLS 1.2 to score an ‘A’? Or are you just staying at a score of a ‘B’ for this and moving on? Any concerns
 you have with moving an IdP from TLS 1.0/1.1 to TLS 1.2?  </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">InCommon wants this all done by mid-July so I’m thinking some of you already started this.
</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Thanks,</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Brent </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal" style="background:white"><b><span style="font-size:13.0pt;font-family:"Times New Roman",serif;color:#201f1e">Brent Goebel</span></b><span style="color:#201f1e"></span></p>
<p class="MsoNormal" style="background:white"><span style="font-family:"Times New Roman",serif;color:#201f1e">Systems Engineer III</span><span style="color:#201f1e"></span></p>
<p class="MsoNormal" style="background:white"><span style="font-family:"Times New Roman",serif;color:#201f1e">Information Technology </span><span style="color:#830033">‖</span><span style="font-family:"Times New Roman",serif;color:#1f497d"> </span><span style="font-family:"Times New Roman",serif;color:#201f1e"> University
 of Denver</span><span style="color:#201f1e"></span></p>
<p class="MsoNormal" style="background:white"><span style="font-family:"Times New Roman",serif;color:#201f1e">2100 </span><span style="font-family:"Times New Roman",serif;color:black">South High Street </span><span style="color:#830033">‖</span><span style="font-family:"Times New Roman",serif;color:#1f497d"> </span><span style="font-family:"Times New Roman",serif;color:black">Denver
 CO 80210</span><span style="color:#201f1e"></span></p>
<p class="MsoNormal" style="background:white"><span style="font-family:"Times New Roman",serif;color:#201f1e"><a href="mailto:brent.goebel@du.edu"><span style="color:blue">brent.goebel@du.edu</span></a></span></p>
<p class="MsoNormal" style="background:white"><span style="color:#201f1e"> </span></p>
<p class="MsoNormal"><img border="0" width="253" height="84" style="width:2.6354in;height:.875in" id="Picture_x0020_1" src="cid:image001.jpg@01D76DB9.DA2600E0" alt="DULogo_IT"></p>
<p class="MsoNormal"> </p>
</div>
</div>
</div>

<div>
<div>
    -- <br>For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div>
</div>
        </blockquote>
    </div>
</div></body></html>