<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>POODLE Archives - MachSol Blog</title>
	<atom:link href="https://blog.machsol.com/tag/poodle/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.machsol.com/tag/poodle</link>
	<description>Multi-Cloud Service Orchestration &#38; Delivery Platform</description>
	<lastBuildDate>Wed, 21 Aug 2019 12:08:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>Time to perform your TLS Version Check &#124; Goodbye TLS1.0 and TLS 1.1 protocols</title>
		<link>https://blog.machsol.com/cloud/perform-tls-version-check-goodbye-tls1-0-tls-1-1-protocols</link>
		
		<dc:creator><![CDATA[Blog-Admin]]></dc:creator>
		<pubDate>Wed, 21 Aug 2019 12:08:43 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[ADFS]]></category>
		<category><![CDATA[Automation Module for Microsoft CSP]]></category>
		<category><![CDATA[hybrid solutions]]></category>
		<category><![CDATA[Microsoft OS]]></category>
		<category><![CDATA[Microsoft Teams]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[POODLE]]></category>
		<category><![CDATA[POODLE attacks]]></category>
		<category><![CDATA[Skype for business server]]></category>
		<category><![CDATA[Skype for Business Server 2015 CU9]]></category>
		<category><![CDATA[Skype for Business Server 2019 CU1]]></category>
		<category><![CDATA[SSL 3.0]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[TLS 1.1 protocols]]></category>
		<category><![CDATA[TLS 1.2]]></category>
		<category><![CDATA[TLS protocols]]></category>
		<category><![CDATA[TLS1.0]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=4458</guid>

					<description><![CDATA[<p>A vulnerability named POODLE was discovered in SSL 3.0. POODLE or Padded Oracle On Downgraded Legacy Encryption that gave a blow to cloud security. Last year, Microsoft had finally taken the decision to turn off the support for all TLS protocols older than TLS 1.2 and SSL v3 last for better cloud security. A decision [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/cloud/perform-tls-version-check-goodbye-tls1-0-tls-1-1-protocols">Time to perform your TLS Version Check | Goodbye TLS1.0 and TLS 1.1 protocols</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;">A vulnerability named POODLE was discovered in SSL 3.0. POODLE or Padded Oracle On Downgraded Legacy Encryption that gave a blow to cloud security. Last year, Microsoft had finally taken the decision to turn off the support for all TLS protocols older than TLS 1.2 and SSL v3 last for better cloud security. A decision that was taken to protect systems against similar POODLE attacks as in the past. It wasn’t easy to get rid of TLS 1.1 and TLS 1.0 so soon, most Microsoft OS and applications had these two protocols hardcoded for a better interoperability experience. Microsoft had to face a bitter backlash as most organizations weren’t ready for the “Change” in its attempt to improve cloud security.</span></p>
<h2><span style="color: #000000;">TLS and the Cloud</span></h2>
<p><span style="color: #000000;">Now Microsoft has decided to turn down support for TLS 1.0 for Office 365 and here’s the real news for CSPs.  Starting 1<sup>st</sup> June, 2020 ( oh yes, less than a year left),  Office 365 is retiring TLS 1.0 and 1.1 (Better perform your TLS version check and get to know your office 365 TLS port today!). The much promised change is going to be implemented for sure this time and all you CSPs out there, it’s high time to upgrade many applications at your end in order to keep things going smooth.  Here’s a list of things that won’t be supported from now on, so, for better cloud security, you need to keep an eye if your organization is still using it:</span></p>
<ul style="list-style-type: square;">
<li><span style="color: #000000;">Firefox version 5.0 and earlier versions</span></li>
<li><span style="color: #000000;">Android 4.3 and earlier versions</span></li>
<li><span style="color: #000000;">Internet Explorer 10 on Windows Phone 8</span></li>
<li><span style="color: #000000;">Safari 6.0.4/OS X10.8.4 and previous versions</span></li>
<li><span style="color: #000000;">Internet Explorer 8-10 on Windows 7 and earlier versions</span></li>
</ul>
<p><span style="color: #000000;">Additionally, Microsoft Teams Room app version 4.0.64.0 or later must be used for conferencing. For Skype for business Server, Skype for Business Server 2015 CU9 (released May 2019) and Skype for Business Server 2019 CU1 (released July 2019) should be deployed organization-wide.</span></p>
<p><span style="color: #000000;">Regarding Infrastructure changes, it is essential to use TLS 1.2 for all inbound and outbound connections in case of on-premises infrastructure for hybrid solutions or ADFS. There are many guides and a</span> <em><a href="https://www.microsoft.com/en-us/download/details.aspx?id=55266">detailed whitepaper</a></em> <span style="color: #000000;">out there for a deep understanding on phasing out TLS 1.0 and TLS 1.1 from your organization.</span></p>
<h2><span style="color: #000000;">MachPanel and Automation Module for Microsoft CSP</span></h2>
<p><span style="color: #000000;">Whether you wish to manage lifecycle of your Direct and Indirect CSP Business or automate it successfully, MachPanel does it for you smoothly. The <a href="https://www.machsol.com/machpanel-automation-for-microsoft-CSP-partners/"><span style="color: #ff1919;">Automation module for Microsoft CSP</span></a> is designed to make sure CSPs get all the assistance they need for a fully automated Cloud business. MachPanel also takes into account the Microsoft enhancements on weak protocols and the experts at MachSol are more than ready to</span> <a href="https://blog.machsol.com/cloud/guide-to-disable-sslv3-and-other-weak-protocols-for-cloud-securityhttps:/blog.machsol.com/cloud/guide-to-disable-sslv3-and-other-weak-protocols-for-cloud-security">guide you against attacks like POODLE</a> <span style="color: #000000;">and others like GOLDENDOODLE. With MachPanel, you can do much with less from a single user friendly interface like control the billing, showcase, bundle and sell your products, monitor business progress with a BI Dashboard and much more. The experts at MachPanel can also guide you through your office 365 TLS port checking and TLS version check.</span></p>
<p><span style="color: #000000;">Stick around for more updates and get your business equipped with MachPanel, for a safer and updated Cloud business.</span></p>
<p style="text-align: center;"><a style="padding: 8px 12px; border: 0; font-weight: normal; letter-spacing: 0.0625em; margin-right: 12px; background: #e61d26; color: #fff; text-decoration: none;" href="https://www.machsol.com/contact-us/">Lets Talk</a><a style="padding: 8px 12px; border: 0; font-weight: normal; letter-spacing: 0.0625em; background: #e61d26; color: #fff; text-decoration: none;" href="https://www.machsol.com/machpanel-enterprise-cloud-hosting-panel/demo-request/">Request a Demo</a></p>
<p>The post <a href="https://blog.machsol.com/cloud/perform-tls-version-check-goodbye-tls1-0-tls-1-1-protocols">Time to perform your TLS Version Check | Goodbye TLS1.0 and TLS 1.1 protocols</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A guide to disable SSLv3 and other weak protocols for Cloud Security</title>
		<link>https://blog.machsol.com/cloud/guide-to-disable-sslv3-and-other-weak-protocols-for-cloud-security</link>
		
		<dc:creator><![CDATA[Blog-Admin]]></dc:creator>
		<pubDate>Tue, 16 Jul 2019 10:19:09 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[afety of cloud]]></category>
		<category><![CDATA[Bleichenbacher]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Control Panel]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[disable SSLv3]]></category>
		<category><![CDATA[Enterprise Turnkey Solutions]]></category>
		<category><![CDATA[GOLDENDOODLE]]></category>
		<category><![CDATA[IIS Crypto]]></category>
		<category><![CDATA[IISCrypto tool]]></category>
		<category><![CDATA[MachPanel]]></category>
		<category><![CDATA[Nartac]]></category>
		<category><![CDATA[POODLE]]></category>
		<category><![CDATA[SSL 2]]></category>
		<category><![CDATA[SSL 3]]></category>
		<category><![CDATA[SSL v3 disabled]]></category>
		<category><![CDATA[SSLv3]]></category>
		<category><![CDATA[TLS 1.0]]></category>
		<category><![CDATA[WHMCS]]></category>
		<category><![CDATA[Windows Server]]></category>
		<guid isPermaLink="false">https://blog.machsol.com/?p=4417</guid>

					<description><![CDATA[<p>Admins prefer to disable SSLv3 to ensure Cloud security as it is a major issue in the cloud computing space. Tools like IIS Crypto are used by Server administrators to disable weak ciphers and protocols. Weak protocols like TLS 1.0 SSL 2 and SSL 3 are make the cloud vulnerable to cyber-attacks. In the midst [&#8230;]</p>
<p>The post <a href="https://blog.machsol.com/cloud/guide-to-disable-sslv3-and-other-weak-protocols-for-cloud-security">A guide to disable SSLv3 and other weak protocols for Cloud Security</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Admins prefer to disable SSLv3 to ensure Cloud security as it is a major issue in the cloud computing space. Tools like IIS Crypto are used by Server administrators to disable weak ciphers and protocols. Weak protocols like TLS 1.0 SSL 2 and SSL 3 are make the cloud vulnerable to cyber-attacks. In the midst of security planning and deploying security solution, many clients opt to disable weak protocols as there step to ensure security in their cloud systems. Attacks like POODLE, GOLDENDOODLE, Bleichenbacher etc. are more popular these days and to prevent these, it is best to disable weak protocols like it is recommended to disable SSLv3.</p>
<p>Organizations like financial institutes mainly banks implement huge security mechanisms but at the same time they often request to disable weak protocols that can be used to exploit any vulnerability. Organizations also request to disable SSLv3 for safety of cloud. Not only ciphers or protocols, weak hashes like MD5 Hashes also need to be disabled for better security.</p>
<h3><strong>Using IIS crypto to disable SSLv3</strong></h3>
<p>In order to disable SSL 3, a serer administrator should best practices in order to ensure security. One of the best practices can be applied by IISCrypto tool from Nartac. This is done to perform the desired registry changes on a Windows Server. This makes the admins perform the necessary steps to disable SSL 3 on the server host.</p>
<h3><strong>Issues on previous builds</strong></h3>
<p>Previous MachPanel builds didn’t allow admins to disable SSLv3 directly since they stopped admins from gaining access via API. In that case, there was a error displayed, once the admin clicks on &#8220;Login to control panel&#8221; from WHMCS to login directly to MachPanel. The error and its details are:</p>
<p><strong><em>Error</em></strong><em>: “Operation failed.Error in fetching tenant details from office 365.</em></p>
<p><strong><em>Details</em></strong><em>: Error processing command: System.Management.Automation.RemoteException: Authentication Error: Unable to complete authentication request (potentially a proxy issue)</em></p>
<p>In such a case the error would only go away if you would SSL 3 back ON.</p>
<h3><strong>The Solution</strong></h3>
<p>In the modern builds of MachPanel, this feature to disable SSL 3 is fully supported. Now, you can disable weak protocols are hashes with all other MachPanel services running intact.</p>
<p>If SSL v3 is disabled, the following command needs to be run before Connect-MsolService command:</p>
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12;</p>
<p>This fixes the previously occurring error message in the latest MachPanel build. More details on the solution can be found <span style="color: #ff0000;"><a style="color: #ff0000;" href="https://kb.machsol.com/Knowledgebase/55610/Disabling-weak-protocols-and-hashes-such-as-SSL-and-TLS-on-basis-of-security">here</a></span>.</p>
<p>With this solution, a good combination of efficiency and cloud security is achieved and the cloud systems can be protected from increasing vulnerabilities in the cyberspace.</p>
<h2><strong>MachPanel and Automation module for CSPs</strong></h2>
<p>CSPs opt for <span style="color: #ff0000;"><a style="color: #ff0000;" href="https://www.machsol.com/products/machpanel/">MachPanel</a></span> because of its user-friendly approach and seamless services whether it is SharePoint migrations, Microsoft Dynamics operations, Microsoft Exchange Server migrations, Microsoft Skype for Business migrations and many other modern cloud services. It gives you the end-to-end lifecycle management of your cloud business which eventually scales your business in the right direction for future growth. The security feature is provided as a must for its customers and it is ensured for all systems. In addition to this, MachPanel provides robust <a href="https://www.machsol.com/services/turnkey-enterprise-solutions/"><span style="color: #ff0000;">Enterprise Turnkey Solutions</span></a> which include Multi-Datacenter and Highly Available Exchange, Skype4B with Enterprise voice and Unified Messaging.  The whole process is seamlessly smooth from Planning to post-project support. The certified experts make it easier with quick turnaround time and easier and secure installation, up-gradations and migrations.</p>
<p>Get your hands on MachPanel for a worry-free experience and seamless business operations with excellent cloud security.</p>
<p style="text-align: center;"><a style="padding: 8px 12px; border: 0; font-weight: normal; letter-spacing: 0.0625em; margin-right: 12px; background: #e61d26; color: #fff; text-decoration: none;" href="https://www.machsol.com/contact-us/">Lets Talk</a><a style="padding: 8px 12px; border: 0; font-weight: normal; letter-spacing: 0.0625em; background: #e61d26; color: #fff; text-decoration: none;" href="https://www.machsol.com/machpanel-enterprise-cloud-hosting-panel/demo-request/">Request a Demo</a></p>
<p>The post <a href="https://blog.machsol.com/cloud/guide-to-disable-sslv3-and-other-weak-protocols-for-cloud-security">A guide to disable SSLv3 and other weak protocols for Cloud Security</a> appeared first on <a href="https://blog.machsol.com">MachSol Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
