Internet Explorer modification - October 24

Friday, October 24, 2014

What is happening? We are making a security modification to Internet Explorer (IE) on academic support computers to enable TLS 1.1 and TLS 1.2, in addition to the current TLS 1.0 and SSL3.0.

When is this happening? Friday October 24 at 5:00 pm

Why is this being done? Versions of IE prior to IE11 are not currently negotiating Transport Layer Security (TLS) 1.1 or 1.2, falling back instead to version 1.0 or SSL 3.0. SSL3.0 can be exploited by the POODLE vulnerability (See: https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/  )

What is the impact? No user impact is expected. This has been successfully deployed and tested on IST staff machines.

After the upgrade: The new settings can be verified by going into Internet Explorer and selecting “Internet Options/”Advanced” tab/and scrolling to the bottom. You should see “Use SSL3.0”, “Use TLS 1.0” and the new, TLS 1.1 and TLS 1.2 checked. Now IE will start negotiating with secure web servers using TLS 1.2 first, down to SSL3.0.)

Questions/concerns? Please contact the IST Service Desk, helpdesk@uwaterloo.ca or ext. 44357.

  1. 2019 (81)
    1. September (5)
    2. August (12)
    3. July (9)
    4. June (9)
    5. May (13)
    6. April (8)
    7. March (8)
    8. February (7)
    9. January (10)
  2. 2018 (112)
    1. December (6)
    2. November (7)
    3. October (8)
    4. September (10)
    5. August (9)
    6. July (11)
    7. June (11)
    8. May (12)
    9. April (9)
    10. March (8)
    11. February (5)
    12. January (16)
  3. 2017 (113)
    1. December (11)
    2. November (11)
    3. October (9)
    4. September (8)
    5. August (6)
    6. July (6)
    7. June (16)
    8. May (10)
    9. April (7)
    10. March (7)
    11. February (13)
    12. January (9)
  4. 2016 (136)
  5. 2015 (203)
  6. 2014 (210)
  7. 2013 (95)
  8. 2012 (187)
  9. 2011 (120)
  10. 2010 (114)
  11. 2009 (233)
  12. 2008 (100)
  13. 2007 (2)