SlideShare a Scribd company logo
© 2019 AppViewX, Inc. 1
The TLS Upgrade
Migrating Away from TLS 1.0 and 1.1
© 2019 AppViewX, Inc. 2
2
Agenda
Implications of the TLS Deprecation
The Upgrade: Challenges and Recommendations
2
3
A Brief History of TLS1
How AppViewX Assists the TLS Migration4
© 2019 AppViewX, Inc. 3
A Brief History of TLS
TLS 1.2 is Released TLS 1.3 is Released
TLS 1.0 & 1.1 will
be deprecated.
TLS 1.1 is ReleasedTLS 1.0 is Released
 Major Browsers
announce early
2020 end-of-
support for TLS
1.0, 1.1
 [Apple, Google,
Mozilla,
Microsoft]
(+) Cipher Suite
Specified
Pseudorandom
Functions
(+) AES Cipher Suites
(+) Functional
Enhancements
(-) IDEA Cipher Suites
(-) DES Cipher Suites
Minor Upgrade to
TLS 1.0
(+) Protection
Against Cipher
Block Chaining
(CBC) Attacks
(+) Single Round-
Trip Handshake
(+) Encryption of
SNI Info
(+) RSA-PSS Support
(-) SHA-1
(-) MD5
(-) RC4
(-) DES
(-) 3ES
 A replacement
to SSL 3.0
 Similar to SSL,
but prevents
interoperability
1999 2006 2008 2018 2020
© 2019 AppViewX, Inc. 4
The Immediate Effects of TLS Deprecation
Loss of recognition
from Big 4 Internet
Browsers
Once deprecated, clients can no longer connect to services using TLS 1.0 and 1.1.
Result:
Exposure to
vulnerabilities of
older versions
(Ex: Downgrade Attacks,
Failing PCI Compliance
Checks)
PCI Supports TLS 1.1 and upwards, strongly
recommends TLS 1.2
© 2019 AppViewX, Inc. 5
Preparing for an Upgrade
Renew x.509 Certificates
Replace/Update Web
Servers
Ensure Application and API
Support of TLS 1.2/1.3
Configure TLS Securely
© 2019 AppViewX, Inc. 6
TLS 1.2 vs. TLS 1.3
TLS 1.3 is fairly recent, with TLS 1.2 being over a decade old. According to Mozilla, 93% of TLS
sessions in 2018 used TLS 1.2, with only 5.6% using TLS 1.3. However, TLS 1.3 boasts of vastly
greater performance and experts recommend its use right away.
Being a newer protocol, TLS 1.3 has several key advantages over its predecessor.
Zero/One Round-Trip Handshakes
Removal of SHA-1, DES, AES-CBC etc.
No Vulnerability to RC4, BEAST
exploits
Perfect Forward Secrecy
RSA-PSS Standard Implementation
Provision to Encrypt SNI Information
© 2019 AppViewX, Inc. 7
Migrating to TLS 1.2/1.3 : Challenges
o The average organization has thousands of applications and
systems supporting TLS 1.0 or 1.1.
o Each application has one or more devices supporting TLS 1.0 or
1.1.
o Manually switching every device to TLS 1.0 is tedious and error-
prone.
o An automation tool that can efficiently migrate/update the
device to TLS 1.2/1.3-compatible ones is a safe, cost-effective
method.
© 2019 AppViewX, Inc. 8
Migrating to TLS 1.2/1.3 : Recommendations
 Configure end systems to disable TLS 1.0/1.1
 Identify technology to replace vulnerable protocols
and document secure configurations to be
implemented.
 Identify all system components and data flows that
rely on OR support the obsolete protocols.
 Ensure that servers are TLS 1.2/1.3 cipher
compatible.
 Discover and verify endpoint compatibility with TLS
1.2 and above.
 Endpoint rectification by enabling TLS 1.2 and above.
 Block vulnerable ciphers (TLS 1.0, 1.1) on endpoints
and plan for a quick rollback if needed.
© 2019 AppViewX, Inc. 9
How can I prime my PKI to work with an upgraded TLS?
Identify Vulnerable Devices
Scan your entire network to
discover and locate Clients
and Servers
Migrate Certificate Keys
Migrate the hash function
from SHA1 to SHA256 to
support TLS 1.2 and above
Renew Certificates
Contact CAs to renew
certificates with the SHA256
key type.
Push to Endpoints
Install the renewed
certificates on their
respective endpoints.
© 2019 AppViewX, Inc. 10
End-to-End Automation Platform: AppViewX CERT+
Growing List of Integrations
ITSM
Web App Firewall
Firewall
Access Proxy
CA
DDI
SSL Certificates
ADC
HSM
SDN, Branch, NFV
© 2019 AppViewX, Inc. 11
Accelerated Certificate Renewal and Installation
Automated installation on endpoints
Achieve an up-to-date certificate infrastructure
Scan environments and discover vulnerable devices
Set up an automation workflow for bulk renewals
Group them according to replacement criteria
© 2019 AppViewX, Inc. 12
CA-Agnostic Discovery Engine
Certificate Discovery Control Panel
Inventory Report
© 2019 AppViewX, Inc. 13
Zero-touch Control over Certificate Infrastructure
Holistic View of
Certificate Trust
Chain
© 2019 AppViewX, Inc. 14
Process Automation with Visual Workflows
Certificate
Process
Workflow
Builder
© 2019 AppViewX, Inc. 15
Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints
Step 1: Select Endpoint(s)
© 2019 AppViewX, Inc. 16
Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints
Step 2: Check current version of endpoint(s)
© 2019 AppViewX, Inc. 17
Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints
Step 3: Disable TLS 1.0/1.1 on endpoint(s)
© 2019 AppViewX, Inc. 18
Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints
Step 4: Implementation of TLS 1.0/1.1 disablement
© 2019 AppViewX, Inc. 19
Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints
Step 5: Check TLS version post disablement of vulnerable version
© 2019 AppViewX, Inc. 20
Value Proposition of Certificate Lifecycle Automation
ELIMINATE
ERRORS
Remove manual
steps in development and
production
ENFORCE
COMPLIANCE
Deliver and
protect applications
as you intend
MOVE
FASTER
Automate network
infrastructure
services
REDUCE
COST
Take out
complexity and
do more with less
© 2019 AppViewX, Inc. 21
Real-world Business Benefits of AppViewX
Reduction in
Issuance Time
Reduction in
Deployment Time
Reduction in
Configuration Time
70% 83% 70% 0%
Configuration
Errors
0%
Outages
© 2019 AppViewX, Inc. 22
Schedule a Live Demo

More Related Content

PPTX
Integrating with salesforce
PDF
見終わったらすぐできる! VMware & Nutanix ユーザーのためのTerraform Cloud
PPTX
Salesforce Integration Pattern Overview
PDF
Replicate Salesforce Data in Real Time with Change Data Capture
PPTX
PUBLISHING YOUR PACKAGE TO APPEXCHANGE IN 2023
PDF
Introduction to the Salesforce Security Model
PPTX
How to Use Telegraf and Its Plugin Ecosystem
PPTX
Platform Events by Tim Taylor
Integrating with salesforce
見終わったらすぐできる! VMware & Nutanix ユーザーのためのTerraform Cloud
Salesforce Integration Pattern Overview
Replicate Salesforce Data in Real Time with Change Data Capture
PUBLISHING YOUR PACKAGE TO APPEXCHANGE IN 2023
Introduction to the Salesforce Security Model
How to Use Telegraf and Its Plugin Ecosystem
Platform Events by Tim Taylor

What's hot (20)

PDF
FIWARE Wednesday Webinars - The Use of DDS Middleware in Robotics (Part 1)
PDF
LinkedInSaxoBankDataWorkbench
PDF
Designing the Next Generation of Data Pipelines at Zillow with Apache Spark
PDF
F5 TLS & SSL Practices
PPTX
Design API using RAML - basics
PDF
Data Migration Done Right for Microsoft Dynamics 365/CRM
PDF
Apex Enterprise Patterns: Building Strong Foundations
PPTX
Top 10 Cypher Tuning Tips & Tricks
PDF
Linux-HA Japanプロジェクトのこれまでとこれから
PDF
Deployment Strategies Powerpoint Presentation Slides
PPTX
Einstein Analytics
PDF
Spark SQL Bucketing at Facebook
PPTX
Data Migration Made Easy
PDF
Secure Access – Anywhere by Prisma, PaloAlto
PPTX
Health monitoring and dependency injection - CNUG November 2019
PPTX
Capture the Streams of Database Changes
PDF
Salesforce.comの情報セキュリティについて
DOC
T24-TAFJ-Consultant_Sivashankar.R
PDF
A Trifecta of Real-Time Applications: Apache Kafka, Flink, and Druid
FIWARE Wednesday Webinars - The Use of DDS Middleware in Robotics (Part 1)
LinkedInSaxoBankDataWorkbench
Designing the Next Generation of Data Pipelines at Zillow with Apache Spark
F5 TLS & SSL Practices
Design API using RAML - basics
Data Migration Done Right for Microsoft Dynamics 365/CRM
Apex Enterprise Patterns: Building Strong Foundations
Top 10 Cypher Tuning Tips & Tricks
Linux-HA Japanプロジェクトのこれまでとこれから
Deployment Strategies Powerpoint Presentation Slides
Einstein Analytics
Spark SQL Bucketing at Facebook
Data Migration Made Easy
Secure Access – Anywhere by Prisma, PaloAlto
Health monitoring and dependency injection - CNUG November 2019
Capture the Streams of Database Changes
Salesforce.comの情報セキュリティについて
T24-TAFJ-Consultant_Sivashankar.R
A Trifecta of Real-Time Applications: Apache Kafka, Flink, and Druid
Ad

Similar to The TLS Upgrade (20)

PPT
Securing Servers in Public and Hybrid Clouds
PPTX
Checkpoint Overview
PPTX
Customer Highleveloverview
PDF
Pivotal Cloud Foundry 2.3: A First Look
PPTX
Friendly Technologies- Cloud-Based TR-069 Device Management Suite
PPSX
NetScaler 11 Update
PDF
Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
PDF
Tech Talk - Cloud Transformation in 2017
PPTX
TechWiseTV Workshop: OpenDNS and AnyConnect
PDF
SSL VPN Evaluation Guide
PPTX
Network-chapter 4.pptx
PPT
Web Services and Devices Profile for Web Services (DPWS)
PPTX
PPT ON WEB SECURITY BY MONODIP SINGHA ROY
PPTX
SECURE SOCKET LAYER ( WEB SECURITY )
PDF
CERT_ver-1.4
PPTX
World Wide Technology Introduces Cisco ONE
PPTX
Slash Avionics Integration Costs with DO-178C Certifiable Connectivity Software
PDF
Istio Service Mesh
PPTX
Adaptive Cloud Security Next Generation Sec
PDF
Presentation capturing the cloud opportunity
Securing Servers in Public and Hybrid Clouds
Checkpoint Overview
Customer Highleveloverview
Pivotal Cloud Foundry 2.3: A First Look
Friendly Technologies- Cloud-Based TR-069 Device Management Suite
NetScaler 11 Update
Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
Tech Talk - Cloud Transformation in 2017
TechWiseTV Workshop: OpenDNS and AnyConnect
SSL VPN Evaluation Guide
Network-chapter 4.pptx
Web Services and Devices Profile for Web Services (DPWS)
PPT ON WEB SECURITY BY MONODIP SINGHA ROY
SECURE SOCKET LAYER ( WEB SECURITY )
CERT_ver-1.4
World Wide Technology Introduces Cisco ONE
Slash Avionics Integration Costs with DO-178C Certifiable Connectivity Software
Istio Service Mesh
Adaptive Cloud Security Next Generation Sec
Presentation capturing the cloud opportunity
Ad

More from AppViewX (20)

PPTX
Accelerate Digital Transformation with Application Delivery Automation
PPTX
Best Practices for Certificate Management
PPTX
Network Automation and Microservices Application
PPTX
AppViewX and Ansible
PPTX
What is NetOps? | NetOps Transformation
PDF
Network Security Automation_Solution Brief
PDF
Application Delivery Automation_Solution Brief
PDF
AppViewX Automation+ brochure
PDF
AppViewX CERT+ Brochure
PDF
AppViewX Platform Brochure
PDF
AppViewX| Case study - Automated server rotations save healthcare consortium ...
PDF
AppViewX|Case study - Largest US telecommunication company builds agile adc i...
PDF
App viewx cert+
PDF
Webinar what's new in avx 12.0 AppViewX
PDF
Webinar unlock the power of adc management and automation AppViewX
PDF
Webinar The New Automation+ developed for Net-ops agility- Appviewx
PDF
Webinar start your automation journey AppViewx
PDF
Operational Efficiency Increases by 40% for Multinational Hotel Chain
PDF
Large Financial Services Company Reduces Deployment Time by 75%
PDF
Global Financial Firm Simplifies Cisco ANM Migration
Accelerate Digital Transformation with Application Delivery Automation
Best Practices for Certificate Management
Network Automation and Microservices Application
AppViewX and Ansible
What is NetOps? | NetOps Transformation
Network Security Automation_Solution Brief
Application Delivery Automation_Solution Brief
AppViewX Automation+ brochure
AppViewX CERT+ Brochure
AppViewX Platform Brochure
AppViewX| Case study - Automated server rotations save healthcare consortium ...
AppViewX|Case study - Largest US telecommunication company builds agile adc i...
App viewx cert+
Webinar what's new in avx 12.0 AppViewX
Webinar unlock the power of adc management and automation AppViewX
Webinar The New Automation+ developed for Net-ops agility- Appviewx
Webinar start your automation journey AppViewx
Operational Efficiency Increases by 40% for Multinational Hotel Chain
Large Financial Services Company Reduces Deployment Time by 75%
Global Financial Firm Simplifies Cisco ANM Migration

Recently uploaded (20)

PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PDF
Hybrid model detection and classification of lung cancer
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
A novel scalable deep ensemble learning framework for big data classification...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
WOOl fibre morphology and structure.pdf for textiles
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
Encapsulation theory and applications.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
OMC Textile Division Presentation 2021.pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Univ-Connecticut-ChatGPT-Presentaion.pdf
Hybrid model detection and classification of lung cancer
NewMind AI Weekly Chronicles - August'25-Week II
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Encapsulation_ Review paper, used for researhc scholars
Group 1 Presentation -Planning and Decision Making .pptx
MIND Revenue Release Quarter 2 2025 Press Release
A novel scalable deep ensemble learning framework for big data classification...
Digital-Transformation-Roadmap-for-Companies.pptx
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
cloud_computing_Infrastucture_as_cloud_p
WOOl fibre morphology and structure.pdf for textiles
Hindi spoken digit analysis for native and non-native speakers
Encapsulation theory and applications.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf

The TLS Upgrade

  • 1. © 2019 AppViewX, Inc. 1 The TLS Upgrade Migrating Away from TLS 1.0 and 1.1
  • 2. © 2019 AppViewX, Inc. 2 2 Agenda Implications of the TLS Deprecation The Upgrade: Challenges and Recommendations 2 3 A Brief History of TLS1 How AppViewX Assists the TLS Migration4
  • 3. © 2019 AppViewX, Inc. 3 A Brief History of TLS TLS 1.2 is Released TLS 1.3 is Released TLS 1.0 & 1.1 will be deprecated. TLS 1.1 is ReleasedTLS 1.0 is Released  Major Browsers announce early 2020 end-of- support for TLS 1.0, 1.1  [Apple, Google, Mozilla, Microsoft] (+) Cipher Suite Specified Pseudorandom Functions (+) AES Cipher Suites (+) Functional Enhancements (-) IDEA Cipher Suites (-) DES Cipher Suites Minor Upgrade to TLS 1.0 (+) Protection Against Cipher Block Chaining (CBC) Attacks (+) Single Round- Trip Handshake (+) Encryption of SNI Info (+) RSA-PSS Support (-) SHA-1 (-) MD5 (-) RC4 (-) DES (-) 3ES  A replacement to SSL 3.0  Similar to SSL, but prevents interoperability 1999 2006 2008 2018 2020
  • 4. © 2019 AppViewX, Inc. 4 The Immediate Effects of TLS Deprecation Loss of recognition from Big 4 Internet Browsers Once deprecated, clients can no longer connect to services using TLS 1.0 and 1.1. Result: Exposure to vulnerabilities of older versions (Ex: Downgrade Attacks, Failing PCI Compliance Checks) PCI Supports TLS 1.1 and upwards, strongly recommends TLS 1.2
  • 5. © 2019 AppViewX, Inc. 5 Preparing for an Upgrade Renew x.509 Certificates Replace/Update Web Servers Ensure Application and API Support of TLS 1.2/1.3 Configure TLS Securely
  • 6. © 2019 AppViewX, Inc. 6 TLS 1.2 vs. TLS 1.3 TLS 1.3 is fairly recent, with TLS 1.2 being over a decade old. According to Mozilla, 93% of TLS sessions in 2018 used TLS 1.2, with only 5.6% using TLS 1.3. However, TLS 1.3 boasts of vastly greater performance and experts recommend its use right away. Being a newer protocol, TLS 1.3 has several key advantages over its predecessor. Zero/One Round-Trip Handshakes Removal of SHA-1, DES, AES-CBC etc. No Vulnerability to RC4, BEAST exploits Perfect Forward Secrecy RSA-PSS Standard Implementation Provision to Encrypt SNI Information
  • 7. © 2019 AppViewX, Inc. 7 Migrating to TLS 1.2/1.3 : Challenges o The average organization has thousands of applications and systems supporting TLS 1.0 or 1.1. o Each application has one or more devices supporting TLS 1.0 or 1.1. o Manually switching every device to TLS 1.0 is tedious and error- prone. o An automation tool that can efficiently migrate/update the device to TLS 1.2/1.3-compatible ones is a safe, cost-effective method.
  • 8. © 2019 AppViewX, Inc. 8 Migrating to TLS 1.2/1.3 : Recommendations  Configure end systems to disable TLS 1.0/1.1  Identify technology to replace vulnerable protocols and document secure configurations to be implemented.  Identify all system components and data flows that rely on OR support the obsolete protocols.  Ensure that servers are TLS 1.2/1.3 cipher compatible.  Discover and verify endpoint compatibility with TLS 1.2 and above.  Endpoint rectification by enabling TLS 1.2 and above.  Block vulnerable ciphers (TLS 1.0, 1.1) on endpoints and plan for a quick rollback if needed.
  • 9. © 2019 AppViewX, Inc. 9 How can I prime my PKI to work with an upgraded TLS? Identify Vulnerable Devices Scan your entire network to discover and locate Clients and Servers Migrate Certificate Keys Migrate the hash function from SHA1 to SHA256 to support TLS 1.2 and above Renew Certificates Contact CAs to renew certificates with the SHA256 key type. Push to Endpoints Install the renewed certificates on their respective endpoints.
  • 10. © 2019 AppViewX, Inc. 10 End-to-End Automation Platform: AppViewX CERT+ Growing List of Integrations ITSM Web App Firewall Firewall Access Proxy CA DDI SSL Certificates ADC HSM SDN, Branch, NFV
  • 11. © 2019 AppViewX, Inc. 11 Accelerated Certificate Renewal and Installation Automated installation on endpoints Achieve an up-to-date certificate infrastructure Scan environments and discover vulnerable devices Set up an automation workflow for bulk renewals Group them according to replacement criteria
  • 12. © 2019 AppViewX, Inc. 12 CA-Agnostic Discovery Engine Certificate Discovery Control Panel Inventory Report
  • 13. © 2019 AppViewX, Inc. 13 Zero-touch Control over Certificate Infrastructure Holistic View of Certificate Trust Chain
  • 14. © 2019 AppViewX, Inc. 14 Process Automation with Visual Workflows Certificate Process Workflow Builder
  • 15. © 2019 AppViewX, Inc. 15 Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints Step 1: Select Endpoint(s)
  • 16. © 2019 AppViewX, Inc. 16 Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints Step 2: Check current version of endpoint(s)
  • 17. © 2019 AppViewX, Inc. 17 Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints Step 3: Disable TLS 1.0/1.1 on endpoint(s)
  • 18. © 2019 AppViewX, Inc. 18 Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints Step 4: Implementation of TLS 1.0/1.1 disablement
  • 19. © 2019 AppViewX, Inc. 19 Custom Workflow: Auto-Disabling TLS 1.0/1.1 on Endpoints Step 5: Check TLS version post disablement of vulnerable version
  • 20. © 2019 AppViewX, Inc. 20 Value Proposition of Certificate Lifecycle Automation ELIMINATE ERRORS Remove manual steps in development and production ENFORCE COMPLIANCE Deliver and protect applications as you intend MOVE FASTER Automate network infrastructure services REDUCE COST Take out complexity and do more with less
  • 21. © 2019 AppViewX, Inc. 21 Real-world Business Benefits of AppViewX Reduction in Issuance Time Reduction in Deployment Time Reduction in Configuration Time 70% 83% 70% 0% Configuration Errors 0% Outages
  • 22. © 2019 AppViewX, Inc. 22 Schedule a Live Demo