{"id":27036,"date":"2022-10-18T11:41:21","date_gmt":"2022-10-18T09:41:21","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=27036"},"modified":"2022-10-18T11:41:21","modified_gmt":"2022-10-18T09:41:21","slug":"sonderupdates-fr-windows-fixen-ssl-tls-verbindungsproblem-auch-bei-citrix-17-oktober-2022","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/10\/18\/sonderupdates-fr-windows-fixen-ssl-tls-verbindungsproblem-auch-bei-citrix-17-oktober-2022\/","title":{"rendered":"Out-of-band updates for Windows fixes SSL-\/TLS connection issues (also with Citrix) &#8211; October 17, 2022"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Update\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; float: left; margin: 0px 10px 0px 0px; display: inline; border-top-width: 0px\" border=\"0\" alt=\"Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/06\/Update-01.jpg\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/10\/18\/sonderupdates-fr-windows-fixen-ssl-tls-verbindungsproblem-auch-bei-citrix-17-oktober-2022\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]As of October 17, 2022, Microsoft has released an unscheduled update KB5020387 for Windows 11 21H2. This update fixes a connection problem that can occur with SSL and TLS connections. All Windows client and server versions that are still in support are probably affected by this problem. The update also fixes a connection issue with Citrix clients that I just reported on.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg07.met.vgwort.de\/na\/05d5fe00f2b54b71a586516143be50fe\" width=\"1\" height=\"1\">Since September 2022 I received reports about issues with SSL and TLS connections on Windows. I had warned about this potential issue in the blog post <a href=\"https:\/\/borncity.com\/win\/2022\/10\/11\/windows-10-achtung-vor-einem-mglichen-tls-desaster-zum-oktober-2022-patchday\/\">Windows 10: Beware of a possible TLS disaster on October 2022 patchday<\/a> . There has been a user report, that the optional, cumulative (preview) update KB5017380 from September 2022 (<a href=\"https:\/\/borncity.com\/win\/2022\/09\/21\/windows-10-20h2-21h2-preview-update-kb5017380-20-9-2022\/\">Windows 10 20H2-21H2 Preview Update KB5017380 (Sept. 20, 2022)<\/a>). There, TLS 1.0 and 1.1 are disabled for certain Windows versions. <\/p>\n<p>My interpretation was, that this may be the root cause, but there seems to be another bug shipped with October 2022 security updates. I have had two blog posts about issues:<\/p>\n<p><a href=\"https:\/\/borncity.com\/win\/2022\/10\/18\/citrix-verbindungen-nach-windows-update-kb5018410-oktober-2022-gestrt-tls-problem\/\">Citrix connections broken after Windows update KB5018410 (October 2022) (TLS problem)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/10\/10\/bug-outlook-stellt-keine-verbindung-mehr-zum-e-mail-server-her-oktober-2022\/\">Bug: Outlook no longer connects to the mail server (October 2022)<\/a>&nbsp; <\/p>\n<p>And Microsoft has released accidential the September 2022 preview update to WSUS (see <a href=\"https:\/\/borncity.com\/win\/2022\/09\/23\/preview-updates-chaos-am-wsus-updates-fr-windows-und-net-zum-21-9-2022-als-superseded-zurckgezogen\/\">WSUS chaos: Preview updates for Windows and Net withdrawn as superseded on 9\/21\/2022<\/a><a href=\"https:\/\/www.borncity.com\/blog\/2022\/09\/23\/preview-updates-chaos-am-wsus-updates-fr-windows-und-net-zum-21-9-2022-als-superseded-zurckgezogen\/\">)<\/a>. But I don't know, whether this has an effect on the current report. Nevertheless, German blog reader commented on my blog post <a href=\"https:\/\/www.borncity.com\/blog\/2022\/10\/18\/citrix-verbindungen-nach-windows-update-kb5018410-oktober-2022-gestrt-tls-problem\/\" target=\"_blank\" rel=\"noopener\">Citrix-Verbindungen nach Windows-Update KB5018410 (Oktober 2022) gest\u00f6rt (TLS-Problem)<\/a>, that this issue has been fixed with the out-of-band Windows updates dates October 17, 2022. <\/p>\n<h2>Out-of-band fixes for SSL-\/TLS connection issues<\/h2>\n<p>Then, as of October 17, 2022, Microsoft posted <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/release-health\/status-windows-10-21H2#2924msgdesc\" target=\"_blank\" rel=\"noopener\">SSL\/TLS handshake might fail<\/a> in the \"Known issues\" section of the <a href=\"https:\/\/docs.microsoft.com\/de-de\/windows\/release-health\/\" target=\"_blank\" rel=\"noopener\">Windows 10 Release Health status page<\/a> (and also for <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/release-health\/status-windows-11-21H2\" target=\"_blank\" rel=\"noopener\">Windows 11<\/a> and for <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/release-health\/status-windows-server-2022\" target=\"_blank\" rel=\"noopener\">Windows Server 2022<\/a>). There, Microsoft confirms that it has received reports that handshake errors may occur after installing KB5018410 (for Windows 11 21H2) for some types of Secure Sockets Layer (SSL) and Transport Layer Security (TLS) connections.<\/p>\n<blockquote>\n<p>For developers, there is an indication that the affected connections are likely sending multiple frames within a single input buffer, that is, one or more full records with a partial record that is less than 5 bytes, all sent in a single buffer. If this problem occurs, your application will receive SEC_E_ILLEGAL_MESSAGE if the connection fails.<\/p>\n<\/blockquote>\n<p>The affected entry can be found for various Windows versions. Here is the list of updates for the affected Windows versions:<\/p>\n<ul>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020387\" target=\"_blank\" rel=\"noopener\">KB5020387<\/a>: Windows 11 21H2\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020435\" target=\"_blank\" rel=\"noopener\">KB5020435<\/a>: Windows 10 20H2 &#8211; 21H2\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020438\" target=\"_blank\" rel=\"noopener\">KB5020438<\/a>: Windows 10 Enterprise 2019 LTSC, Windows Server 2019\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020436\" target=\"_blank\" rel=\"noopener\">KB5020436<\/a>: Windows Server 2022\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020447\" target=\"_blank\" rel=\"noopener\">KB5020447<\/a>: Windows 8.1, Windows Server 2012 R2\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020449\" target=\"_blank\" rel=\"noopener\">KB5020449<\/a>: Windows Server 2012\n<li><a href=\"https:\/\/support.microsoft.com\/help\/5020448\" target=\"_blank\" rel=\"noopener\">KB5020448<\/a>: Windows 7 SP1, Windows Server 2008 R2<\/li>\n<\/ul>\n<p>These special updates are only available for download in the <a href=\"https:\/\/www.catalog.update.microsoft.com\/Home.aspx\" target=\"_blank\" rel=\"noopener\">Microsoft Update Catalog<\/a>&nbsp; and must be installed manually (simply search for the KB numbers). Details about these updates can be found in the linked KB articles. <\/p>\n<p><strong>Similar article:<br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/2022\/09\/21\/windows-10-20h2-21h2-preview-update-kb5017380-20-9-2022\/\">Windows 10 20H2-21H2 Preview Update KB5017380 (Sept. 20, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/10\/11\/windows-10-achtung-vor-einem-mglichen-tls-desaster-zum-oktober-2022-patchday\/\">Windows 10: Beware of a possible TLS disaster on October 2022 patchday<\/a>&nbsp;<br \/><a href=\"https:\/\/borncity.com\/win\/2022\/10\/18\/citrix-verbindungen-nach-windows-update-kb5018410-oktober-2022-gestrt-tls-problem\/\">Citrix connections broken after Windows update KB5018410 (October 2022) (TLS problem)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/10\/10\/bug-outlook-stellt-keine-verbindung-mehr-zum-e-mail-server-her-oktober-2022\/\">Bug: Outlook no longer connects to the mail server (October 2022)<\/a>&nbsp;<br \/><a href=\"https:\/\/borncity.com\/win\/2022\/09\/23\/preview-updates-chaos-am-wsus-updates-fr-windows-und-net-zum-21-9-2022-als-superseded-zurckgezogen\/\">WSUS chaos: Preview updates for Windows and Net withdrawn as superseded on 9\/21\/2022<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]As of October 17, 2022, Microsoft has released an unscheduled update KB5020387 for Windows 11 21H2. This update fixes a connection problem that can occur with SSL and TLS connections. All Windows client and server versions that are still in &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/10\/18\/sonderupdates-fr-windows-fixen-ssl-tls-verbindungsproblem-auch-bei-citrix-17-oktober-2022\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,2],"tags":[466,195,194],"class_list":["post-27036","post","type-post","status-publish","format-standard","hentry","category-update","category-windows","tag-problem","tag-update","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/27036","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=27036"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/27036\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=27036"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=27036"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=27036"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}