{"id":18095,"date":"2021-01-09T00:10:00","date_gmt":"2021-01-08T23:10:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=18095"},"modified":"2021-01-08T18:12:11","modified_gmt":"2021-01-08T17:12:11","slug":"nsa-security-advisory-on-obsolete-tls-configurations","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/01\/09\/nsa-security-advisory-on-obsolete-tls-configurations\/","title":{"rendered":"NSA security advisory on obsolete TLS configurations"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/?p=241249\" target=\"_blank\" rel=\"noopener\">German<\/a>]Information for administrators in server environments. Communication with (web) servers should be performed with current TLS 1.2 or TLS 1.3 encryption. Fallback to older TLS 1.0\/1.1 or SSL standards should be removed. The US National Security Agency (NSA) has issued recommendations on this.<\/p>\n<p><!--more--><\/p>\n<p>The National Security Agency (NSA) strongly recommends replacing outdated TLS protocol configurations with those that use strong encryption and authentication to protect all sensitive information. Over time, new attacks have been discovered against Transport Layer Security (TLS) and the algorithms used in these attacks. Network connections using outdated protocols are at increased risk of being exploited by attackers. <\/p>\n<p><a href=\"https:\/\/twitter.com\/endi24\/status\/1346806998613041153\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"NSA-Empfehlungen zu TLS\" alt=\"NSA-Empfehlungen zu TLS\" src=\"https:\/\/i.imgur.com\/vJyFIWL.png\"><\/a><\/p>\n<p>Thorsten E. pointed out the NSA recommendations in the above <a href=\"https:\/\/twitter.com\/endi24\/status\/1346806998613041153\" target=\"_blank\" rel=\"noopener\">tweet<\/a> the other day, which can be read in the document <a href=\"https:\/\/media.defense.gov\/2021\/Jan\/05\/2002560140\/-1\/-1\/0\/ELIMINATING_OBSOLETE_TLS_UOO197443-20.PDF\" target=\"_blank\" rel=\"noopener\">Eliminating Obsolete Transport Layer Security (TLS)<\/a> (PDF). <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Information for administrators in server environments. Communication with (web) servers should be performed with current TLS 1.2 or TLS 1.3 encryption. Fallback to older TLS 1.0\/1.1 or SSL standards should be removed. The US National Security Agency (NSA) has issued &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/01\/09\/nsa-security-advisory-on-obsolete-tls-configurations\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-18095","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/18095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=18095"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/18095\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=18095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=18095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=18095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}