{"id":7651,"date":"2018-11-12T00:14:00","date_gmt":"2018-11-11T23:14:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=7651"},"modified":"2023-07-19T17:09:50","modified_gmt":"2023-07-19T15:09:50","slug":"microsofts-tls-issues","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/11\/12\/microsofts-tls-issues\/","title":{"rendered":"Microsoft&rsquo;s TLS issues"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[German]Microsoft is planning to end support for TLS 1.0\/1.1 in its products (Windows, Office 365 etc.) and switch to TLS 1.2\/1.3. But it seems that this will cause some trouble at the moment. Here's a short summary of what I noticed the last days. <\/p>\n<p><!--more--><\/p>\n<h2>Some background about TLS<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/ssl-vg03.met.vgwort.de\/na\/96908bd85b7a445fbf6c2c395bf2b540\" width=\"1\" height=\"1\"><a href=\"https:\/\/en.wikipedia.org\/wiki\/Transport_Layer_Security\" target=\"_blank\" rel=\"noopener\">Transport Layer Security<\/a> (TLS) is a cryptographic protocols designed to provide communications security over a computer network. Historically, different TLS versions from 1.0, 1.1 to 1.2 and recently TLS 1.3 have been defined and are in use. Since encryption in TLS 1.0 and 1.1 is no longer considered secure, the IT industry is gradually trying to switch to TLS 1.2 and\/or TLS 1.3 for secure Internet connections. In June 2018 there was <a href=\"https:\/\/www.theregister.co.uk\/2018\/06\/19\/ietf_calls_for_formal_tls_1_0_1_1_deprecation\/\" target=\"_blank\" rel=\"noopener\">this article<\/a> from The Register that the IETF had started to make suggestions that TLS 1.0\/1.1 (also as a fallback solution) should be deprecated. Browser manufacturers announced to end support for TLS 1.0\/1.1 in 2020. Microsoft is also committed to replacing TLS 1.0\/1.1, but has noticeable difficulties. <\/p>\n<blockquote>\n<p>Note: However, the topic is quite broken in some places. Recently <a href=\"https:\/\/www.zdnet.com\/article\/many-cms-plugins-are-disabling-tls-certificate-validation-and-thats-very-bad\/\" target=\"_blank\" rel=\"noopener\">this ZDNet article<\/a> pointed out that numerous Content Management Systems (CMS) or their plugins deactivate the validation of TLS certificates. But this is another construction site.&nbsp; <\/p>\n<\/blockquote>\n<h2>End of support for TLS 1.0\/1.1 in Office 365 revised<\/h2>\n<p>I mentioned it briefly in June 2018 in the blog post <a href=\"https:\/\/borncity.com\/win\/2018\/06\/06\/psa-eol-for-tls-1-0-1-1-support-in-intune-and-office-365\/\">PSA: EOL for TLS 1.0\/1.1 support in Intune and Office 365<\/a>: Within <a href=\"https:\/\/blogs.technet.microsoft.com\/intunesupport\/2018\/06\/05\/intune-moving-to-tls-1-2-for-encryption\/\" target=\"_blank\" rel=\"noopener\">this Technet blog<\/a> post, Microsoft announced that Intune would only support TLS 1.2 after October 31, 2018. Microsoft Office 365 will then also only be able to communicate with TLS 1.2 via https encryption (see <a href=\"https:\/\/support.microsoft.com\/de-de\/help\/4057306\/preparing-for-tls-1-2-in-office-365\" target=\"_blank\" rel=\"noopener\">also<\/a>). For administrators in corporate environments, this means that a number of devices and software products can no longer be used from the deadline 31.10.2018 due to a lack of TLS 1.2 support (I mentioned the devices in the blog post).<\/p>\n<p>Microsoft is now clarified what 'end of support' means. At the end of October 2018 I found the article <a href=\"https:\/\/redmondmag.com\/articles\/2018\/10\/26\/microsoft-revises-tls-deadline.aspx\" target=\"_blank\" rel=\"noopener\">Microsoft Revises October Deadline on Using TLS 1.0 and 1.1 in Office 365<\/a> in Redmond Magazine. They mentioned a change within Microsoft's article <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4057306\/preparing-for-tls-1-2-in-office-365\" target=\"_blank\" rel=\"noopener\">Preparing to use TLS 1.2 in Office 365<\/a>.<\/p>\n<blockquote>\n<p>As of October 31, 2018, Office 365 will no longer support TLS 1.0 and 1.1. This means that Microsoft will not fix new issues that are found in clients, devices, or services that connect to Office 365 by using TLS 1.0 and 1.1.  <\/p>\n<p><strong>Note<\/strong> This doesn't mean Office 365 will block TLS 1.0 and 1.1 connections. There is no official date for disabling or removing TLS 1.0 and 1.1 in the TLS service for customer connections. The eventual deprecation date will be determined by customer telemetry and is not yet known. After a decision is made, there will be an announcement six months in advance <em>unless we become aware of a known compromise, in which case we may have to act in less than six months to protect customers who use the services<\/em>.<\/p>\n<\/blockquote>\n<h2>Update KB4462923 forced TLS 1.0?<\/h2>\n<p>On October 9, 2018, Microsoft released the Monthly Rollup Update <a href=\"https:\/\/support.microsoft.com\/en-ca\/help\/4462923\/windows-7-update-kb4462923\" target=\"_blank\" rel=\"noopener\">KB4462923<\/a> for Windows 7 SP1 and Windows Server 2008 R2 Service Pack 1. I mentioned the update in my blog post Patchday: Updates for Windows 7\/8.1\/Server (10\/09\/2018). However, there were some installation issues (see <a href=\"https:\/\/borncity.com\/win\/2018\/11\/03\/windows-7-sp1-update-kb4462923-re-released\/\">Windows 7 SP1: Update KB4462923 re-released?<\/a> and <a href=\"https:\/\/borncity.com\/win\/2018\/10\/17\/windows-update-issues-and-re-releases-october-2018\/\">Windows: Update issues and \u2013re-releases October 2018<\/a>). The update has been withdrawn and later re-released again. I lost track what Microsoft did with this update. A German blog reader posted a <a href=\"https:\/\/www.borncity.com\/blog\/2018\/10\/13\/windows-10-update-error-0x80242006\/#comment-63922\" target=\"_blank\" rel=\"noopener\">comment<\/a>, indicating that an update install error 0x80242006 may has something to do with TLS dependencies in .NET-Framework. But I have not details.&nbsp; <\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p lang=\"en\" dir=\"ltr\">Report: The October Win7 Monthly rollup, KB 4462923, forces TLS 1.0 as the default protocol type, even when TLS 1.0 is disabled. Can you confirm? <a href=\"https:\/\/t.co\/Zg5ZVWNaFv\">https:\/\/t.co\/Zg5ZVWNaFv<\/a><\/p>\n<p>\u2014 Woody Leonhard (@woodyleonhard) <a href=\"https:\/\/twitter.com\/woodyleonhard\/status\/1060961198534000641?ref_src=twsrc%5Etfw\">9. November 2018<\/a><\/p><\/blockquote>\n<p><span id=\"preservec472b32957104b1ea5f2a164eb745d01\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>Now <a href=\"https:\/\/www.askwoody.com\/2018\/report-the-october-win7-monthly-rollup-kb-4462923-forces-tls-1-0\/\" target=\"_blank\" rel=\"noopener\">Woody Leonhard reported at askwoody<\/a>, that update KB4462923 for Windows 7 SP1 force TLS 1.0 again. A reader of Woody's site posted the following comment:<\/p>\n<blockquote>\n<p>I'm not sure what others are experiencing but, at my place of employment, KB4462923 appears to have changed the system default crypto security protocol type to TLS 1.0 even when TLS 1.0 is disabled both client-side and server-side in the system registry.&nbsp; Since we have TLS 1.0 disabled on all of our production servers (Windows Server 2008 R2 SP1), KB4462923 was responsible for a plethora of application failures from basic database mail delivery failures to application connectivity failures with Microsoft Azure cloud solutions; most definitely a showstopping bug for our business.<\/p>\n<\/blockquote>\n<p>Within the thread at askwoody.com some users pointing out issues with Outlook 2010, but it's not clear, whether it has something to do with TLS.&nbsp; <\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p lang=\"en\" dir=\"ltr\">In addition, from my experience, <a href=\"https:\/\/twitter.com\/PowerShell_Team?ref_src=twsrc%5Etfw\">@PowerShell_Team<\/a> demands TLS v1.0 for several Modules including PowershellGet &amp; PowershellManagement.<\/p>\n<p>I have had TLS v1.0 &amp; v1.1 turned off with Powershell being the only App that breaks.<\/p>\n<p>\u2014 Crysta T. Lacey (@PhantomofMobile) <a href=\"https:\/\/twitter.com\/PhantomofMobile\/status\/1061316911890259968?ref_src=twsrc%5Etfw\">10. November 2018<\/a><\/p><\/blockquote>\n<p><span id=\"preservedb94e3d348c346e68358a6a29693df9d\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>User @PhantomofMobile has pointed out in thetweet above that the PowerShell team requires TLS 1.0 for various PS modules, including PowershellGet and PowershellManagement. Somehow it all smells like problems to me. Question: Have you noticed anything similar or are there other problems?&nbsp; <\/p>\n<p><strong>Similar articles<br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/2018\/08\/18\/windows-10-v1803-update-kb4458166-fixes-tls-1-2-issue\/\">Windows 10 V1803: Update KB4458166 fixes TLS 1.2 issue<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/18\/tls-1-2-windows-error-reporting-service-drops-an-error\/\">TLS 1.2: Windows Error Reporting Service drops an error<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/15\/windows-10-v1803-rollout-stopped-due-to-tls-1-2-issues\/\">Windows 10 V1803 rollout stopped due to TLS 1.2 issues<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/06\/06\/psa-eol-for-tls-1-0-1-1-support-in-intune-and-office-365\/\">PSA: EOL for TLS 1.0\/1.1 support in Intune and Office 365<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/11\/03\/windows-7-sp1-update-kb4462923-re-released\/\">Windows 7 SP1: Update KB4462923 re-released?<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/10\/17\/windows-update-issues-and-re-releases-october-2018\/\">Windows: Update issues and \u2013re-releases October 2018<\/a><br \/>Patchday: Updates for Windows 7\/8.1\/Server (10\/09\/2018)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft is planning to end support for TLS 1.0\/1.1 in its products (Windows, Office 365 etc.) and switch to TLS 1.2\/1.3. But it seems that this will cause some trouble at the moment. Here's a short summary of what I &hellip; <a href=\"https:\/\/borncity.com\/win\/2018\/11\/12\/microsofts-tls-issues\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,580,2],"tags":[125,69,194],"class_list":["post-7651","post","type-post","status-publish","format-standard","hentry","category-office","category-security","category-windows","tag-office","tag-security","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7651","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=7651"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7651\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=7651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=7651"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=7651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}