News: 1693836914

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft calls time on ancient TLS in Windows, breaking own stuff in the process

(2023/09/04)


Microsoft has reminded users that TLS 1.0 and 1.1 will soon be disabled by default in Windows.

While home users of Windows are unlikely to notice many issues, Microsoft [1]warned that choppy waters could lie ahead for enterprise administrators. It [2]published a non-exhaustive list of applications that it said were "expected to be broken."

Top of the list is SQL Server. The 2014 and 2016 editions, both of which remain in support, [3]could require updates . SQL Server 2012, which is currently in [4]Extended Security Updates , is also on the list.

[5]

SQL Server 2008 R2 finally dropped out of Extended Security Updates in July, although Microsoft has published instructions for adding TLS 1.2 support.

[6]

[7]

The list of applications Microsoft expects to be broken also includes version 5.1.7 of Apple's Safari browser for Windows and, without a hint of irony, several security applications.

As Reg readers know, Transport Layer Security (TLS) is a protocol for encrypting communications between a client and server and dates back to the last century. The current standard, which has been used since 2018, is TLS 1.3. TLS 1.2 was published in 2008, and both represent significant improvements over their predecessors.

[8]

Microsoft's desire to dispense with deprecated versions of TLS has been well documented. However, the requirement to maintain backwards compatibility has prevented the company from pulling the plug on the technology until now.

The Redmond software giant said: "We have been tracking TLS protocol usage for several years and believe TLS 1.0 and TLS 1.1 usage data are low enough to act."

Although the company may be acting in the coming weeks and months – Windows Insiders will be the first to have TLS 1.0 and 1.1 disabled by default from September, followed by future Windows releases – the option to re-enable the protocols will remain.

[9]

However, it won't be a straightforward job for administrators using that one old app that simply must use the deprecated standards. Microsoft warned that a registry setting would be needed to override the system default.

The company thundered: "Re-enabling TLS 1.0 or TLS 1.1 on machines should only be done as a last resort and as a temporary solution until incompatible applications can be updated or replaced. Support for these legacy TLS versions may be removed completely in the future."

[10]Microsoft admits slim staff and broken automation contributed to Azure outage

[11]Farewell WordPad, we hardly knew ye

[12]Official: Microsoft unbundles Teams in Europe

[13]After injecting pop-up ads for Bing into Windows, Microsoft now bends to Europe on links

Stamping out deprecated versions of TLS has been a goal of the industry for several years; the US National Security Agency (NSA) [14]published guidance on eliminating the tech in 2021 and three years earlier, Apple, Microsoft, Google, and Mozilla [15]announced plans to move on from the outdated protocols.

Microsoft's progress has moved in fits and starts since then. It had initially planned to disable TLS 1.0 and 1.1 by default in Edge and Internet Explorer 11 in the first half of 2020 but moved this back to [16]2021 . It then set [17]September 20, 2022 as the date for Internet Explorer and EdgeHTML. The protocols were disabled by default in Chromium Edge from version 84.

A year on, and the company is gearing up to disable by default the protocols in its flagship operating system. ®

Get our [18]Tech Resources



[1] https://learn.microsoft.com/en-gb/windows/release-health/windows-message-center#3153

[2] https://techcommunity.microsoft.com/t5/windows-it-pro-blog/tls-1-0-and-tls-1-1-soon-to-be-disabled-in-windows/ba-p/3887947

[3] https://learn.microsoft.com/en-US/troubleshoot/sql/database-engine/connect/tls-1-2-support-microsoft-sql-server

[4] https://learn.microsoft.com/en-us/lifecycle/products/microsoft-sql-server-2012

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZPX-I9XOQsGAXAW7ZGUujgAAARI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPX-I9XOQsGAXAW7ZGUujgAAARI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPX-I9XOQsGAXAW7ZGUujgAAARI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPX-I9XOQsGAXAW7ZGUujgAAARI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPX-I9XOQsGAXAW7ZGUujgAAARI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2023/09/04/microsoft_australia_outage_incident_report/

[11] https://www.theregister.com/2023/09/04/microsoft_deprecates_wordpad/

[12] https://www.theregister.com/2023/08/31/microsoft_to_unbundle_teams/

[13] https://www.theregister.com/2023/08/30/microsoft_windows_11_bing/

[14] https://www.cisa.gov/news-events/alerts/2021/01/05/nsa-releases-guidance-eliminating-obsolete-tls-protocol

[15] https://security.googleblog.com/2018/10/modernizing-transport-security.html

[16] https://blogs.windows.com/msedgedev/2018/10/15/modernizing-tls-edge-ie11/

[17] https://blogs.windows.com/msedgedev/2020/03/31/tls-1-0-tls-1-1-schedule-update-edge-ie11/

[18] https://whitepapers.theregister.com/



protocols were disabled by default

Bruce Ordway

I need it to keep some older "stuff" working so am already in the habit of re-enabling TLS versions on Windows and Linux.

But... that's just a few personal PC's on my home LAN.

For enterprises I'd be a little more concerned...

Re: protocols were disabled by default

Paul Crawford

For enterprises I'd be a little more concerned...

I would hope, but don't expect, that enterprise systems would properly segment the network so such legacy TLS systems are not facing the world or those machines used for web/email access.

Re: protocols were disabled by default

Anonymous Coward

The problem is that the people holding the purse strings don't seem to understand that these things happen in a way that you, the techie, can't control.

Give them a choice of not being secure while using WAN services vs. not being able to talk to that piece of legacy hardware that you've been asking to replace for years but they won't stump up the money, and they will choose internet security, and expect you to just fix it!

Fortunately, where I am (which is actually quite a sensitive environment), it finally looks like they will finally fund the replacement of the tape libraries and management consoles that are running code so old it's fallen off the suppliers compatibility matrix!

Hopefully.

Pretty Please?

Lee D

Ran IISCrypto last year and enabled it's best practice mode on all the servers on my new workplace.

Who the hell relies on early TLS still? And Microsoft doing it now "because usage has fallen to an acceptable level", in essence? How ridiculous for an outdated and insecure security-based protocol with a clear path to replacement/upgrade for years now.

"Fantasies are free."
"NO!! NO!! It's the thought police!!!!"