Wednesday, February 15, 2017

TLS 1.3 Adoption


On 5 April 2017 OpenSSL 1.1.1, which implements TLS (Transport Layer Security) 1.3 will be released. OpenSSL 1.1.1 will maintain compatibility with version 1.1.0. TLS 1.3 contains important updates to both, 0-RTT, and the removal of numerous legacy ciphers vulnerable to cryptographic attacks. Current and planned adoptions of TLS 1.3 on commonly used platforms: Cloudflare on 20 September 2016; Chrome version 56+ on 25 January 2017; Opera version 53+ on 7 February 2017; Firefox version 52+ on 17 March 2017; OpenSSL 1.1.1+ on 5 April 2017; Akamai TBD after OpenSSL release. Wireshark, the most prevalent network protocol analyzer, currently does not support TLS 1.3 with version 2.2.4. However, development is currently in progress and the status can be seen on the Wireshark Bugzilla. 

Wapack Labs has reported on encryption protocols in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

TLP: GREEN
ACTOR TYPE: (N/A)
SERIAL: TR-035-2017
COUNTRIES: ALL
INDUSTRIES: ALL
REPORT DATE: 20170214