Security upgrades to website

Date: Thu, 28 Mar 2013 15:00:16 -0400 (AST)
From: "Andrew D. Wright" <awright@chebucto.ns.ca>
To: help-answers@chebucto.ns.ca
Precedence: bulk
Return-Path: <help-answers-mml-owner@chebucto.ns.ca>
Original-Recipient: rfc822;"| (cd /csuite/info/lists/help-answers; /csuite/lib/arch2html)"

next message in archive
no next message in thread
previous message in archive
Index of Subjects



 	Hi all. This is just a heads-up to everyone about some security 
upgrades we've put in.

 	We have upgraded our handling of secure pages and dropped support 
for older insecure protocols. Our web server secure pages are now rated A 
for security.

 	This should only affect very old and outdated browsers but we've 
since heard that some Internet Explorer users, even with recent versions 
(IE 9, IE 10) may be unable to access Chebucto secure pages because the 
support for the TLS protocols may be unchecked in their settings.

 	The fix for this is easy. Control Panel -> Internet Options -> 
Advanced, scroll to the bottom of the window and make sure Use TLS 1.0, 
Use TLS 1.1 and Use TLS 1.2 are checked. Click Apply. Click OK.

 	As far as we know the default Internet Explorer setting for recent 
versions has Use TLS 1.0 (but not versions 1.1 or 1.2) checked by default. 
It's better to be using TLS 1.2 but so long as TLS 1.0 is checked our 
secure pages can be accessed by Internet Explorer. It's only when none of 
the TLS protocols are checked problems accessing our secure pages occur.

 	If someone complains about suddenly (since last week) being 
unable to get their mail and they are using Internet Explorer on our 
Webmail, get them to check their TLS settings.

 	We also heartily recommend Mozilla Firefox, the free browser 
alternative to Internet Explorer, which doesn't have this kind of issue.

next message in archive
no next message in thread
previous message in archive
Index of Subjects