Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reason for reenabling TLS 1.0, TLS 1.1 #188

Closed
mikebell90 opened this issue Apr 20, 2021 · 5 comments
Closed

Reason for reenabling TLS 1.0, TLS 1.1 #188

mikebell90 opened this issue Apr 20, 2021 · 5 comments
Labels
enhancement New feature or request

Comments

@mikebell90
Copy link

I know this has been planned by oracle for a long time. Does amazon have an alternative timeline

6e6fedb

@mikebell90 mikebell90 added the enhancement New feature or request label Apr 20, 2021
@alvdavi
Copy link
Contributor

alvdavi commented Apr 20, 2021

Hi,

One of our distinguished engineers have published an article about this:
https://shufflesharding.com/posts/java-and-tls-10-11

An article with more details will also be published soon in the AWS Blog

@alvdavi
Copy link
Contributor

alvdavi commented Apr 21, 2021

@mikebell90
Copy link
Author

Both of those are well written, clear, and appreciated. The only question I have remaining is "Assuming a dramatic new security issue does not come to light to accelerate the removal timeframe, when is Amazon currently expecting to sunset these"

@davecurrie
Copy link
Contributor

davecurrie commented Apr 21, 2021

I can't commit to a timeline but it won't be long. We will disable them by default as soon as we have a good reason to believe it won't cause problems for many existing applications. Communicating it clearly will help users know about the issue and find/fix problems they may have, to accelerate the process. Direct feedback from our users is another way we will know what is happening.

I will be very happy if it turns out that disabling TLS 1.0/1.1 doesn't cause any problems anywhere and we can do the same in the next updates.

@alvdavi alvdavi pinned this issue Apr 27, 2021
@alvdavi alvdavi closed this as completed Apr 27, 2021
@apara
Copy link

apara commented Apr 20, 2022

@davecurrie any more updates on plans for when TLS 1.0/1.1 will be formally removed out of Corretto? We are currently somewhat dependent on TLS 1.0 / 1.1 functionality due to older hardware constraints. To avoid any surprises, have you guys made any decisions for when TLS 1.0 / 1.1 will be formally removed from the Java 11 builds?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

4 participants