April 19, 2023 TLS 1.0 TLS 1.1 Meraki Disable Test.

CharlieCrackle
A model citizen

April 19, 2023 TLS 1.0 TLS 1.1 Meraki Disable Test.

 I have had a few customers reach out to me about the Merkai Email Sent to them.

 

===================================================

 

Hello valued Meraki customer,
 
Meraki will be discontinuing support for versions 1.0 and 1.1 of the Transport Layer Security (TLS) protocol used by wireless devices to communicate with Meraki Authentication. In order to facilitate the provisioning of enhanced security features, we will be requiring all customers to upgrade, at a minimum, to TLS version 1.2. This change will only affect wireless devices using TLS versions 1.0 and 1.1 when connecting to the Meraki Authentication server.
 
Timing:

Due to security requirements, we do not have the ability to determine which of your devices, if any, are currently using the prior versions of the TLS protocol. In an effort to help you identify these devices, we will be temporarily disabling support for TLS 1.0 and 1.1 as a test. This action will cause a planned disruption of device connectivity, which will begin at 12:00 am PST on April 19, 2023 and end at 12:00 am PST on April 20, 2023. Any devices that experience an issue with connectivity during the test period may be using the prior versions of the TLS protocol.

 

Final retirement of TLS 1.0 and 1.1 will take place on May 17, 2023.

  

Required action:

Please plan for the 24-hour test period accordingly. If any of your devices experience an issue with connectivity during the planned test period outlined above, you may be required to upgrade to TLS 1.2 or a later version. To help you determine where potentially-affected devices may be located, a list of your organizations with Meraki Authentication enabled

 

===================================================

 

 

Why can Merkai not flag the clients using the OLD TLS protocols ???

 

Would make it much easier to know the issues before 19April.   A hospital cannot have wifi devices down for a day for testing.

 

 

 

 

4 Replies 4
PhilipDAth
Kind of a big deal
Kind of a big deal

>Why can Merkai not flag the clients using the OLD TLS protocols ???

 

How?  If you can suggest a method to detect a device that can't connect due to an issue on the device itself, I am sure they would consider incorporating it.

 

>A hospital cannot have wifi devices down for a day for testing.

 

That is probably an easier case.  The Hospital could consult there inventory systems to check that OSs on the different devices to see what needs to be migrated.

CharlieCrackle
A model citizen

Yes I get it now, it was not clear in my head  it is the client end.   I was thinking meraki could list clients that were presenting old protocols.

I was amazed today how many emails I got from clients today regarding this.   Most customers have no clue what their devices support.

 

Kudos to Meraki for having a down day to highlight the issue to customers that have no inventory or IT support any more due to cut backs.

BlakeRichardson
Kind of a big deal
Kind of a big deal

@CharlieCrackle Hospitals and healthcare providers of all people should be ensuring themselves that their devices are using updated and secure protocols. TLS1.0 and 1.1 have been listed as insecure for quite awhile now. 

 

They shouldn't be relying on any system disabling these to find out they are using out of date protocols / software. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
BlakeRichardson
Kind of a big deal
Kind of a big deal

I apologise if my reply was blunt but given the number of hospitals and health care providers that have fallen victim to cyber attacks there isn't an excuse for poor security given the large amount of personal and confidential data they hold. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels