Deprecation of TLS 1.0 and 1.1

Anyone still needs TLS 1.0 and 1.1 when working with MBS Xojo Plugins?

OpenSSL plans to disable them by default. We should do the same.

Everyone moved to TLS 1.2 and 1.3 as far as we know, so nobody should need the older one. The version 1.2 was published in 2008 and most browser already removed support for the older ones.
The older versions had weak ciphers and digest algorithms which shouldn’t be used anymore. It’s too easy to attack such connections and be the man in the middle, who could decipher the content.

Let us know if you still need older versions. Otherwise they will get disabled in future plugins, probably next year.

5 Likes