Just an update to close the string I started.
We turned off SSLv2 and SSLv3 yesterday on our iSeries . So far no issues. I also found out that it is recommended to turn off SSLv2 and SSLv3 on desktop browsers and in desktop java configuration. Which I did on my own PC and have not had any issues there either
Mike Cunningham
VP of Information Technology Services/CIO
Pennsylvania College of Technology
-----Original Message-----
From: MIDRANGE-L [mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of JWGrant@xxxxxxxxxxxxxxx
Sent: Thursday, January 22, 2015 10:40 AM
To: Midrange Systems Technical Discussion
Subject: Re: Turing off SSLv2 and SSLv3 support
Hi Mike:
We just went through this on our PCI environment . We use a free service from qualys ssl labs
https://www.ssllabs.com/ssltest/ This online service tests the ssl certificates and server configuration of the server in question. After ssllabs completes its assessment the report will show a handshake simulation section (along with a ton of other stuff) showing the results of the ssl handshake of various platforms and browsers.
You are correct older browsers like IE 6 will not be able to by default connect with your server. I do think there is a setting in IE 6 that enables TLS 1.0 but its not checked/enabled by default.
Hope this helps.
Jim
Jim W Grant
Senior VP, Chief Information Officer
Web: www.pdpgroupinc.com
From: Mike Cunningham <mike.cunningham@xxxxxxx>
To: Midrange Systems Technical Discussion <midrange-l@xxxxxxxxxxxx>
Date: 01/22/2015 10:11 AM
Subject: Turing off SSLv2 and SSLv3 support
Sent by: "MIDRANGE-L" <midrange-l-bounces@xxxxxxxxxxxx>
Did anyone encounter any issues after turning off SSLv2 and SSLv3 support on their system? Our PCI scan this quarter says it has to be disabled or we will not be considered in compliance. I believe the only issue with doing this is that some users with very old browsers will not be able to negotiate an secure connection.
Thanks
Mike Cunningham
VP of Information Technology Services/CIO Pennsylvania College of Technology
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options,
visit:
http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at
http://archive.midrange.com/midrange-l.
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options,
visit:
http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at
http://archive.midrange.com/midrange-l.
As an Amazon Associate we earn from qualifying purchases.