-
Type: Feature Request
-
Status: Closed (View Workflow)
-
Priority: Major
-
Resolution: Completed
-
Affects Version/s: None
-
Fix Version/s: CFA 2021R2
-
Component/s: None
-
Labels:
-
INF Reference Number:INF-12270
Transport Layer Security (TLS) is used in communication between the Livelink client on the POS server and the Livelink server. The current version in use, TLS 1.0, is no longer supported and has been marked as unsecure by the CFA security team. In order to eliminate the risks that go along with using an unsupported encryption protocol, CFA would like to upgrade from TLS 1.0 to TLS 1.2.
On 01/06/21, CFA said that it is OK to simply go to TLS 1.2
Is TLS 1.0 used in InFORM's production environment? If so, is it possible that it can be disabled and upgraded to TLS 1.2?
Comments:
Will Englefield - September 6, 2019, 9:30 AM
Chris Jones I have sent you the only thread that I have, I haven’t really been involved in this, so I’m a little behind the curve on it
Per comments from Cherlyn Lewis yesterday:
- We use TLS 1.0 in the communication between live link client (on the POS ) and the live link Server. It can be disabled and upgraded to 1.2, but that would require a change on all of the POS Servers
Thanks
Chris Jones September 6, 2019, 12:56 PM
Thanks, Will. Per the email you sent me, Stacy said:
- I am getting more details on the effort needed to upgrade from 1.0 to 1.2 but from a high level discussion this process will go through upgrading the version of .Net that the LiveLink client uses. This would require a recompile and full regression of LiveLink, plus redeployment to all of the POS servers.
How much time do you estimate it would take to recompile and regression test LiveLink as well as deploy to all POS servers? Would this need to be included in a release?
Thank you!
Will Englefield September 6, 2019, 1:28 PM
Hi Chris Jones,
Can you please enter a Feature Request for this?
We will need to prioritize and plan for this work to be included in a development sprint, depending on what we find, it may/may not need to be tied to a release. In theory it shouldn’t, but it’s a possibility.
The deployment of LL is done by Chick-fil-A, so you would need to co-ordinate with your internal resources. (I don’t know if you have a new version waiting to be deployed at the moment, or not.)
As a part of the work, in addition to performing a full LL regression, we would test the environment as a whole, using the Sandbox.
Thanks
- is implemented by
-
CFAMX-13047 Testing (S3.R2) - LiveLink - Update TLS from 1.0 to 1.2
- Closed
- is related to
-
CFAMX-13047 Testing (S3.R2) - LiveLink - Update TLS from 1.0 to 1.2
- Closed