Solved

How to find if a webserver is using SSL or TLS

Posted on 2014-11-03
7
195 Views
Last Modified: 2014-11-18
Hello, I received the following from message from Salesforce:  "As an administrator of a Salesforce org that may have recently been accessed using SSL 3.0 encryption, we want to inform you of a change regarding supported encryption protocols. Over the next two months, Salesforce will be disabling SSL 3.0 encryption in a phased approach to prevent it from being used to access the Salesforce platform. "

Salesforce is doing this because of a security vulnerability that affects SSL 3.0.  They are going to use TLS 1.0 encryption or higher.

I would like to find out how to find if our webserver is using SSL 3.0 or TLS.  Also, if it is not using TSL how to enable it.  Thanks
0
Comment
Question by:gloyola1
  • 4
  • 2
7 Comments
 
LVL 14

Accepted Solution

by:
John-Charles-Herzberg earned 100 total points
ID: 40420209
This will help;

This free SSL / TLS web server testing tool conducts a thorough analysis of your SSL / TLS web server configuration and performance. Including protocols, encryption ciphers, known security weaknesses, session caching and much more.

https://www.wormly.com/test_ssl
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 400 total points
ID: 40420234
wormly.com said my site was using SSLv3 when it isn't

You can use this site to test for the Poodle vulnerability (which is why Salesforce are disabling SSLv3)
https://www.poodlescan.com/
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 400 total points
ID: 40420247
You can also go here for how to disable it
http://www.experts-exchange.com/Q_28539415.html
0
Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

 

Author Comment

by:gloyola1
ID: 40420269
I have access to the web server, how can I find out if SSL or TLS is enabled.  If TLS is not enabled how can I enable it.  Thanks
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 400 total points
ID: 40420272
It would be very unusual if TLS wasn't enabled - it's the most widely used form of encryption for SSL and has been for 15 years.
SSLv3 is very rarely used.

What server?
0
 

Author Comment

by:gloyola1
ID: 40420296
2008 r2 web server
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 400 total points
ID: 40420322
Disabling is detailed in the link above.
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We've all had that page pop up telling us there is a problem with the certificate and some of us continue on anyways and others run away to a safer competing site.  But what to do when you get the error - is it your problem or theirs?  What can you …
Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question