5 ms·
This is a bit of a pain for .net devs on 4.5, as it by default has TLS1.2 disabled. You can fix it with System.Net.ServicePointManager.SecurityProtoco
by dc_gregory 9y ago
This is a bit of a pain for .net devs on 4.5, as it by default has TLS1.2 disabled.
You can fix it with
System.Net.ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls11 | SecurityProtocolType.Tls;
but note that its a somewhat global setting (for your appdomain?) so don't just set it to Tls12 and wonder why some of your connections don't work anymore.
- tootie 9y agoIsn't 1.2 like 10 years old? Why would it be disabled?
- jagger27 9y agoIE either did not support it or had it disabled by default up until version 11. That's my guess, anyway. Firefox and Chrome took quite a while to fully implement it too. https://help.salesforce.com/articleView?id=000220586&language=en_US&type=1 https://help.salesforce.com/articleView?id=000220586&languag...
- user5994461 9y agoXP and IE and office up to 2013 and redhat and debian and curl and python and java and openssl and... It took a while for TLS 1.2 to be supported by major platforms and tools.
- craftyguy 9y agoMicrosoft.
- dc_gregory 9y agoAssuming there is a compatibility reason. Also keep in mind, 4.5 was released late 2012 (and support ended at the start of 2016).
- jwilk 9y agoThe spec was published in August 2008. So yes, nearly 10 years. Source: https://tools.ietf.org/html/rfc5246 https://tools.ietf.org/html/rfc5246
- pilif 9y agoBecause of broken interception proxies. In many cases, these prevented connections from being established at all if either side of the connection even just announced 1.2 support. So it was disabled by default and in consequence it remained niche which didn’t exactly improve the situation with broken middle boxes. It also made implementing it in various SSL libraries somewhat low priority (see OpenSSL) Only as the security of pre 1.2 started really crumbling and once the Snowden revelations moved security to somewhat higher priority in the public perception, it started to at least become possible to enable 1.2 at least on servers. Frankly, I'm impressed we actually got to where we are at now. For a long time between 2008 and maybe 2015 it really looked like 1.2 was dead in the water. Now we're transitioning to 1.3 and history is repeating itself: despite going great lengths to hide the differentness of 1.3 to existing middleboxes, they are still breaking 1.3 connections causing more and more bad hacks to be added to the protocol. A protocol which supports version negotiation since the beginnings in the early 90ies btw.
- tootie 9y agoCrumble? AFAIK, there are no known attacks against any version of TLS. Only SSL. Heartbleed was an implementation defect, not a problem with the spec. Same with Snowden. They basically just opened the front door to him.
- hannob 9y agoI just checked, .net 4.5 has been end of life since 2015. So if this causes people to realize that this can only be good.
- taspeotis 9y ago.NET 4.5 RTM has been EOL since 2015, you need to install a newer version like .NET 4.5.2.
- taspeotis 9y agoThis is "fixed" in .NET 4.7 [1], which will take its cues from the operating system by default. So if Windows has TLS 1.2 support enabled, your apps will too. [1] https://docs.microsoft.com/en-us/dotnet/framework/whats-new/#networking-1 https://docs.microsoft.com/en-us/dotnet/framework/whats-new/...
- dc_gregory 9y agoI think in 4.6.1 (maybe 4.6), the default was set to TLS1.2 as well, so the problem was mostly solved a bit earlier. Much cleaner solution to listen to the OS though.