News: 1647372240

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft Azure DevOps revives TLS 1.0/1.1 with rollback

(2022/03/15)


Microsoft's Azure DevOps team has undone the deprecation of outdated Transport Layer Security (TLS) that occurred at the end of January because of unspecified "unexpected issues" that arose following the change.

Last November, Rajesh Ramamurthy, director of product management for Azure DevOps, [1]announced plans to phase out support for TLS 1.0/1.1 because of the risk of protocol downgrade attacks and other TLS vulnerabilities outside Microsoft's control.

TLS downgrade attacks aim to turn strong, more recent versions of TLS into weaker, earlier versions of the protocol to facilitate further exploitation. Some have jolly names like POODLE (Padding Oracle On Downgraded Legacy Encryption)

[2]PDF

and [3]SLOTH (Security Losses from Obsolete and Truncated Transcript Hashes); others aim to be a bit more alarming with monikers like [4]FREAK (factoring RSA export keys) and [5]Logjam .

[6]

Azure DevOps services stopped accepting TLS 1.0/1.1 connections, and at a minimum required TLS 1.2, as of January 31, 2022. This applied to all HTTPS connections to Azure DevOps Services, including web API and git connections to https://dev.azure.com/orgname and https://orgname.visualstudio.com . It did not affect users of the self-hosted Azure DevOps Server.

[7]Moscow to issue HTTPS certs to Russian websites

[8]Alert: Let's Encrypt to revoke about 2 million HTTPS certificates in two days

[9]Microsoft starts 2022 with big bundle fixes for 96 security bugs in its software

[10]NSA: We 'don't know when or even if' a quantum computer will ever be able to break today's public-key encryption

But things did not go entirely as planned and TLS 1.0/1.1 is back for another week or so, for customers connecting over IPv4 endpoints. If you're connecting over IPv6, TLS 1.2 is already enforced as a minimum requirement.

Mark Graham, product manager for Azure DevOps Platform, provided no details beyond citing "unexpected issues," which pretty much covers the gamut of possibilities.

[11]

[12]

Fortunately, relatively few Azure DevOps users are likely to be affected by this hiccup.

"We anticipate minimal impacts to our customers as more than 99.5 per cent of connections made to Azure DevOps Services already use TLS 1.2," said Graham in a [13]blog post . "Clients have TLS 1.2-compatibility issues because of obsolete OS versions or if available updates are not applied (applies for all Windows, macOS and Linux) or legacy .NET Framework installation or OS configuration prohibiting certain TLS cipher suites."

[14]

Microsoft's next attempt to shut down TLS 1.0/1.1 for Azure DevOps is scheduled for March 31, 2022.

Prior to that date, there will be dress-rehearsals that consist of 12-hour test shutdowns of TLS 1.1/1.0 on March 22, 2022, from 09:00 to 21:00 UTC, for https://orgname.visualstudio.com . Then two days later, on March 24, 2022, https://dev.azure.com/orgname will turn off TLS 1.1/1.0 to test for software that fails with TLS 1.2.

Following these tests, the outdated TLS versions will be re-enabled until the end of the month when, barring unexpected issues, the deprecation will be complete.

[15]

At that point, everything will be secure ever after. No, not really. Things will just be incrementally more secure at Azure DevOps.

"We apologize for any disruption this may cause and appreciate your support to improve our security posture," said Graham. ®

Get our [16]Tech Resources



[1] https://devblogs.microsoft.com/devops/deprecating-weak-cryptographic-standards-tls-1-0-and-tls-1-1-in-azure-devops/

[2] https://www.openssl.org/~bodo/ssl-poodle.pdf

[3] https://www.mitls.org/downloads/transcript-collisions.pdf

[4] https://freakattack.com/

[5] https://weakdh.org/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjEaqJJYGv5rzYEGlcwIaQAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://www.theregister.com/2022/03/11/russian_ca/

[8] https://www.theregister.com/2022/01/26/lets_encrypt_certificates/

[9] https://www.theregister.com/2022/01/12/january_patch_tuesday/

[10] https://www.theregister.com/2021/09/01/nsa_quantum_computing_faq/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjEaqJJYGv5rzYEGlcwIaQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjEaqJJYGv5rzYEGlcwIaQAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://devblogs.microsoft.com/devops/deprecating-weak-cryptographic-standards-tls-1-0-and-1-1-in-azure-devops-services/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjEaqJJYGv5rzYEGlcwIaQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjEaqJJYGv5rzYEGlcwIaQAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://whitepapers.theregister.com/



Unix Beer: Comes in several different brands, in cans ranging from 8 oz.
to 64 oz. Drinkers of Unix Beer display fierce brand loyalty, even
though they claim that all the different brands taste almost identical.
Sometimes the pop-tops break off when you try to open them, so you have
to have your own can opener around for those occasions, in which case you
either need a complete set of instructions, or a friend who has been
drinking Unix Beer for several years.
BSD stout: Deep, hearty, and an acquired taste. The official
brewer has released the recipe, and a lot of home-brewers now use it.
Hurd beer: Long advertised by the popular and politically active
GNU brewery, so far it has more head than body. The GNU brewery is
mostly known for printing complete brewing instructions on every can,
which contains hops, malt, barley, and yeast ... not yet fermented.
Linux brand: A recipe originally created by a drunken Finn in his
basement, it has since become the home-brew of choice for impecunious
brewers and Unix beer-lovers worldwide, many of whom change the recipe.
POSIX ales: Sweeter than lager, with the kick of a stout; the
newer batches of a lot of beers seem to blend ale and stout or lager.
Solaris brand: A lager, intended to replace Sun brand stout.
Unlike most lagers, this one has to be drunk more slowly than stout.
Sun brand: Long the most popular stout on the Unix market, it was
discontinued in favor of a lager.
SysV lager: Clear and thirst-quenching, but lacking the body of
stout or the sweetness of ale.