微軟今天宣布,出于安全原因Office 365將不再對SSL
微軟今天宣布,出于安全原因Office 365將不再對SSL3.0提供支持,執行日期將在2014年12月1日。具體問題為近期發現SSL3.0中存在漏洞。
微軟聲明如下:
“我們希望用戶可以閱讀編號為3009008的安全報告,報告中給出了關于Secure Sockets Layer (SSL) 3.0漏洞的詳細信息。這個業界范圍內的漏洞影響廣泛,會導致用戶信息資料被泄露。為保護用戶利益,我們決定將在幾個月內關閉對SSL3.0的支持”
從2014年12月1日開始,Office 365將會停止對SSL3.0的支持,也就是所有客戶端與瀏覽器的組合都需要使用TLS1.0或更高版本來確保對Office 365服務器的連接。
原文:
Microsoft today announced that they are disabling support for SSL 3.0 from December to protect customers from the recently reported vulnerability in SSL 3.0.
We wanted to share details around Security A**isory 3009008. This a**isory provides guidance related to a vulnerability in Secure Sockets Layer (SSL) 3.0 which could allow information disclosure. This is an industry-wide vulnerability that affects the protocol itself and is not specific to Microsoft’s implementation. To help protect our customers further, we will be disabling fallback to SSL 3.0 in IE, disabling SSL 3.0 by default in IE, and across Microsoft online services, over the coming months.
Starting on December 1, 2014, Office 365 will disabe support for SSL 3.0. This means that from December 1, 2014, all client/browser combinations will need to utilize TLS 1.0 or higher to connect to Office 365 services without issues.
本文由花無缺網絡轉載而成,如有侵權 請聯系站長刪除
原創文章,作者:花無缺,如若轉載,請注明出處:http://www.uuuxu.com/20220504302275.html