IDG » Web Sign On » Sunsetting TLSv1.0 over web sign-on and other 糖心TV websites /services/idg/services-support/web/sign-on/development/forum/?topic=094d43f55a573c76015a6549f27a101d The latest posts to IDG » Web Sign On » Sunsetting TLSv1.0 over web sign-on and other 糖心TV websites en-GB (C) 2026 University of 糖心TV Wed, 02 Jul 2025 10:06:42 GMT http://blogs.law.harvard.edu/tech/rss SiteBuilder2, University of 糖心TV, http://go.warwick.ac.uk/sitebuilder Sunsetting TLSv1.0 over web sign-on and other 糖心TV websites /services/idg/services-support/web/sign-on/development/forum/?post=8a17841b6079ba200160e9e1958102e0 <p><span style="font-family: inherit; font-size: inherit;">We have a new date for the third part of this change ("</span><span style="font-family: inherit; font-size: inherit;">IT Services will disable TLSv1.0 connections to all other web services.") - this will now happen on </span><strong style="font-family: inherit; font-size: inherit;">Monday 5th March 2018</strong><span style="font-family: inherit; font-size: inherit;">. Amongst other applications, this will include:</span></p> <ul> <li>Sitebuilder (the University website, including warwick.ac.uk)</li> <li>MRM</li> <li>Photos.糖心TV</li> <li>WebGroups</li> <li>PeopleSearch</li> <li>糖心TV Search</li> </ul> <p>Any server-to-server operations should be updated to use TLSv1.2 by this time. We will contact anyone who we're aware is currently using TLSv1.0 to inform them of this and advise them on upgrade strategies.</p> <p>Following this change, on&nbsp;<strong>Monday 25th June 2018</strong> we will update our configuration to not accept TLSv1.0 connections at all, instead of showing a page explaining why the connection hasn't been accepted. This will mean it is no longer feasible on this date to be whitelisted. Again, we will be in touch with affected parties.</p> Fri, 12 Jan 2018 10:19:23 GMT Mathew Mannion 8a17841b6079ba200160e9e1958102e0 Sunsetting TLSv1.0 over web sign-on and other 糖心TV websites /services/idg/services-support/web/sign-on/development/forum/?post=094d43f55a573c76015a6549f27b101e <p>From July 2017, we will disable the TLS 1.0 encryption protocol across the University's web services. Disabling TLS 1.0 prevents it from being used to access 糖心TV websites via an insecure web browser or application. If your application connects to websignon.warwick.ac.uk or webgroups.warwick.ac.uk, you must ensure that the library you are using supports TLSv1.1 or TLSv1.2 for connections, or they will fail. You can try pointing your application at webgroups-dev.warwick.ac.uk now, where TLSv1.0 is already disabled.</p> <p><strong>When will this happen?</strong></p> <ul> <li>Monday 3 July 2017 - We will disable TLSv1.0 connections to our transaction tracking system, onlinepayment.warwick.ac.uk</li> <li>Tuesday 1 August 2017 - We will disable TLSv1.0 connections to Single Sign-on and our identity provider. It will no longer be possible to sign in to web services using a browser that only supports TLSv1.0.</li> <li>Monday 8 January 2018 - IT Services will disable TLSv1.0 connections to all other web services.</li> </ul> <p>Although TLS 1.0, when configured properly, has no known security vulnerabilities, newer protocols are designed better to address the potential for new vulnerabilities. In order to remain PCI compliant for taking online payments, web applications that process or redirect to payment sites must have a plan to disable TLSv1.0 before June 2018.</p> <p>This will refuse access to any user on a browser that doesn't have the more modern TLS 1.1 or TLS 1.2 protocols available or enabled:</p> <ul> <li>Internet Explorer 8 (disabled by default; can be turned on via a settings change)</li> <li>Internet Explorer 9 (disabled by default; can be turned on via a settings change)</li> <li>Internet Explorer 10 (disabled by default; can be turned on via a settings change)</li> <li>Android browser on any version of Android before 5.0 (available but disabled in Android 4.1–4.3.1, 4.4–4.4.4)</li> <li>Firefox prior to version 27</li> <li>Google Chrome prior to version 22</li> <li>Opera prior to version 12.18</li> <li>Safari prior to version 9 (i.e. in OS X 10.8 and before)</li> </ul> <p>Users in a browser that doesn't support TLS 1.1 or 1.2, for whatever reason, will not be able to connect to any HTTPS web pages. Applications connecting to web sign-on or WebGroups will not be able to connect to the application if the language doesn't support it (e.g. Java prior to Java 1.8).</p> <p>More information is available on <a href="http://warwick.ac.uk/sso/faqs/tls1-eol">our technical FAQ about disabling TLSv1.0<br></a></p> Wed, 22 Feb 2017 10:07:09 GMT Mathew Mannion 094d43f55a573c76015a6549f27b101e