<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://wiki.newhavensoftware.com/index.php?action=history&amp;feed=atom&amp;title=SSL_and_TLS</id>
	<title>SSL and TLS - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://wiki.newhavensoftware.com/index.php?action=history&amp;feed=atom&amp;title=SSL_and_TLS"/>
	<link rel="alternate" type="text/html" href="http://wiki.newhavensoftware.com/index.php?title=SSL_and_TLS&amp;action=history"/>
	<updated>2026-05-15T15:05:19Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.0</generator>
	<entry>
		<id>http://wiki.newhavensoftware.com/index.php?title=SSL_and_TLS&amp;diff=2396&amp;oldid=prev</id>
		<title>Russ horton at 22:36, 13 April 2016</title>
		<link rel="alternate" type="text/html" href="http://wiki.newhavensoftware.com/index.php?title=SSL_and_TLS&amp;diff=2396&amp;oldid=prev"/>
		<updated>2016-04-13T22:36:15Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 22:36, 13 April 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Much &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;has been &lt;/del&gt;made in &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;recent years &lt;/del&gt;about the vulnerabilities of [http://info.ssl.com/article.aspx?id=10241 SSL] and early versions of [https://en.wikipedia.org/wiki/Transport_Layer_Security TLS] as a secure means of establishing a connection between a web server and a browser. The greatest area of concern on this front for our clients has been the related impact and requirements for PCI compliance, particularly the 2016 deadline which was subsequently moved to [http://blog.pcisecuritystandards.org/migrating-from-ssl-and-early-tls June 2018].  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Much &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;was &lt;/ins&gt;made in &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;2015 &lt;/ins&gt;about the vulnerabilities of [http://info.ssl.com/article.aspx?id=10241 SSL] and early versions of [https://en.wikipedia.org/wiki/Transport_Layer_Security TLS] as a secure means of establishing a connection between a web server and a browser. The greatest area of concern on this front for our clients has been the related impact and requirements for PCI compliance, particularly the 2016 deadline which was subsequently moved to [http://blog.pcisecuritystandards.org/migrating-from-ssl-and-early-tls June 2018].  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thankfully, as far as CMS is concerned, there isn&#039;t much to worry about since CMS does not use your browser. CMS TEN (10.0.x) has been validated as compliant against the PA-DSS 3.0 standard which ensured the CMS was not requiring the use of insecure protocols and is compatible with the use of secure protocols. You can find CMS on the PCI Council&#039;s site in their list of [https://www.pcisecuritystandards.org/assessors_and_solutions/payment_applications?agree=true validated payment applications]. (search &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;on application name &lt;/del&gt;CMS - Commerce Management System)&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thankfully, as far as CMS is concerned, there isn&#039;t much to worry about since CMS does not use your browser. CMS TEN (10.0.x) has &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;also &lt;/ins&gt;been validated as compliant against the PA-DSS 3.0 standard which ensured the CMS was not requiring the use of insecure protocols and is compatible with the use of secure protocols. You can find CMS on the PCI Council&#039;s site in their list of [https://www.pcisecuritystandards.org/assessors_and_solutions/payment_applications?agree=true validated payment applications]. (&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;TIP - &lt;/ins&gt;search &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;by Application Name for &#039;&lt;/ins&gt;CMS - Commerce Management System&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&lt;/ins&gt;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;While CMS does enforce/require secure connections be made when credit card data may be passed, CMS is not specifying or requiring a particular security protocol. Instead CMS is relying on Windows and the service provider to handle that handshake to determine which protocol can be used to establish a secure connection. To this end you&amp;#039;ll want to be sure that:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;While CMS does enforce/require secure connections be made when credit card data may be passed, CMS is not specifying or requiring a particular security protocol. Instead CMS is relying on Windows and the service provider to handle that handshake to determine which protocol can be used to establish a secure connection. To this end you&amp;#039;ll want to be sure that:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l8&quot;&gt;Line 8:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 8:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Noting Windows XP and Server 2003 are no longer supported&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Noting Windows XP and Server 2003 are no longer supported&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;B) You are connecting to a service provider/partner that is using/dictating protocols currently deemed secure by PCI.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;B) You are connecting to a service provider/partner that is using/dictating protocols currently deemed secure by PCI&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. These would include the host or your website(s) and payment processor&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;For example, Authorize.net, one of our payment partners, has recently made changes in their systems to address the use of secure versions of TLS. You can read more about this in our wiki article on [[Authorize.net Changes]].&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;For example, Authorize.net, one of our payment partners, has recently made changes in their systems to address the use of secure versions of TLS. You can read more about this in our wiki article on [[Authorize.net Changes]].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Russ horton</name></author>
	</entry>
	<entry>
		<id>http://wiki.newhavensoftware.com/index.php?title=SSL_and_TLS&amp;diff=2394&amp;oldid=prev</id>
		<title>Russ horton at 22:14, 13 April 2016</title>
		<link rel="alternate" type="text/html" href="http://wiki.newhavensoftware.com/index.php?title=SSL_and_TLS&amp;diff=2394&amp;oldid=prev"/>
		<updated>2016-04-13T22:14:08Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 22:14, 13 April 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l10&quot;&gt;Line 10:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 10:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;B) You are connecting to a service provider/partner that is using/dictating protocols currently deemed secure by PCI.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;B) You are connecting to a service provider/partner that is using/dictating protocols currently deemed secure by PCI.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;For example, Authorize.net, one of our payment partners, has recently made changes in their systems to address the use of secure versions of TLS. You can read more about this in our article on [[Authorize.net &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;changes&lt;/del&gt;]].&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;For example, Authorize.net, one of our payment partners, has recently made changes in their systems to address the use of secure versions of TLS. You can read more about this in our &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;wiki &lt;/ins&gt;article on [[Authorize.net &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Changes&lt;/ins&gt;]].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Russ horton</name></author>
	</entry>
	<entry>
		<id>http://wiki.newhavensoftware.com/index.php?title=SSL_and_TLS&amp;diff=2393&amp;oldid=prev</id>
		<title>Russ horton: Created page with &#039;Much has been made in recent years about the vulnerabilities of [http://info.ssl.com/article.aspx?id=10241 SSL] and early versions of [https://en.wikipedia.org/wiki/Transport_Lay…&#039;</title>
		<link rel="alternate" type="text/html" href="http://wiki.newhavensoftware.com/index.php?title=SSL_and_TLS&amp;diff=2393&amp;oldid=prev"/>
		<updated>2016-04-13T19:29:13Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;#039;Much has been made in recent years about the vulnerabilities of [http://info.ssl.com/article.aspx?id=10241 SSL] and early versions of [https://en.wikipedia.org/wiki/Transport_Lay…&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Much has been made in recent years about the vulnerabilities of [http://info.ssl.com/article.aspx?id=10241 SSL] and early versions of [https://en.wikipedia.org/wiki/Transport_Layer_Security TLS] as a secure means of establishing a connection between a web server and a browser. The greatest area of concern on this front for our clients has been the related impact and requirements for PCI compliance, particularly the 2016 deadline which was subsequently moved to [http://blog.pcisecuritystandards.org/migrating-from-ssl-and-early-tls June 2018]. &lt;br /&gt;
&lt;br /&gt;
Thankfully, as far as CMS is concerned, there isn&amp;#039;t much to worry about since CMS does not use your browser. CMS TEN (10.0.x) has been validated as compliant against the PA-DSS 3.0 standard which ensured the CMS was not requiring the use of insecure protocols and is compatible with the use of secure protocols. You can find CMS on the PCI Council&amp;#039;s site in their list of [https://www.pcisecuritystandards.org/assessors_and_solutions/payment_applications?agree=true validated payment applications]. (search on application name CMS - Commerce Management System)&lt;br /&gt;
&lt;br /&gt;
While CMS does enforce/require secure connections be made when credit card data may be passed, CMS is not specifying or requiring a particular security protocol. Instead CMS is relying on Windows and the service provider to handle that handshake to determine which protocol can be used to establish a secure connection. To this end you&amp;#039;ll want to be sure that:&lt;br /&gt;
&lt;br /&gt;
A) You are using a supported Microsoft operating system on your workstations that run CMS&lt;br /&gt;
 Noting Windows XP and Server 2003 are no longer supported&lt;br /&gt;
&lt;br /&gt;
B) You are connecting to a service provider/partner that is using/dictating protocols currently deemed secure by PCI.&lt;br /&gt;
&lt;br /&gt;
For example, Authorize.net, one of our payment partners, has recently made changes in their systems to address the use of secure versions of TLS. You can read more about this in our article on [[Authorize.net changes]].&lt;/div&gt;</summary>
		<author><name>Russ horton</name></author>
	</entry>
</feed>