Quantcast
Viewing all articles
Browse latest Browse all 2161

Re: TLS_FALLBACK_SCSV (server-side)

Hi Martin,

 

That simply isn't true. Although the deadline has changed from June 30th 2016 to June 30th 2018 (just before I made my last post, unbeknownst to me), migrating away from early TLS is still a requirement of PCI-DSS 3.1. Please see:

 

https://www.pcisecuritystandards.org/documents/Migrating_from_SSL_Early_TLS_Information%20Supplement_v1.pdf

 

Date Change for Migrating from SSL and Early TLS

 

https://www.pcisecuritystandards.org/pdfs/15_12_18_SSL_Webinar_Press_Release_FINAL.pdf

 

The PCI firm we work with have confirmed that they have received clarification on this point from the Council. TLS 1.1 and TLS 1.2 are OK to continue to use. SSL 3.0 and TLS 1.0 are not OK to continue to use unless you have a Risk Mitigation and Migration Plan. Furthermore, if anything flags up with a CVSS score of 4.0 or higher (as SSL 3.0 invariably does) then you can't pass a PCI-DSS assessment, so SSL 3.0 is really gone already.

 

To make things absolutely clear: TLS 1.0 is not OK any more, and if your organisation processes card payments, you either have to drop it, or have a documented plan to drop it by June 30th 2018. Interop is not a valid excuse to support TLS 1.0 past this date.


Viewing all articles
Browse latest Browse all 2161

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>