FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > FutureQuest Site Owners (All may read - Only Site Owners May Respond) > News & Announcements
User Name
Password  Lost PW

View Poll Results: TLSv1.0 Support
I would not be affected by dropping TLS 1.0 Support 6 66.67%
I would be affected by dropping TLS 1.0 Support 0 0%
PCI Compliance is worth breaking things 0 0%
What the heck is TLS 1.0 3 33.33%
Multiple Choice Poll. Voters: 9. You may not vote on this poll

 
Thread Tools Search this Thread Display Modes
Old 09-22-2016, 07:30 PM   Postid: 185377
abrams
Site Owner

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Dec 2001
Posts: 12
Re: PCI Compliance - TLSv1.0 Encryption Support

Why did we not receive a warning about this? You just shut down my entire business. Not good.

This is not like futurequest to not send out warnings and notices that this was coming.
abrams is offline  
Old 09-22-2016, 07:37 PM   Postid: 185378
 Terra
CTO FutureQuest, Inc.
 
Terra's Avatar
 
Join Date: Jun 1998
Location: Z'ha'dum
Posts: 8,108
Re: PCI Compliance - TLSv1.0 Encryption Support

This notice was posted: 04-27-2016, 05:29 AM

The main issue was getting this fixed quickly for some clients that were having failed PCI compliance scans which are integral to their ecommerce operations... We generally react quite quickly to such things and given the writing on the wall was posted back in April of 2016, we went ahead and pulled the trigger to fix current client complaints...

If this has shutdown your entire business, please detail exactly how removing TLSv1.0 has done so and we'll see if we can find a workaround...
__________________
The FutureQuest Team
Terra is offline  
Old 09-22-2016, 07:43 PM   Postid: 185379
abrams
Site Owner

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Dec 2001
Posts: 12
Re: PCI Compliance - TLSv1.0 Encryption Support

Posted?

Are you serious? Do you think this forum is really THE place to announce this?

Why were clients not sent emails regarding this?

You knew about this problem since APRIL OF 2016 and you sent nothing out to your clients.

The only effort you made was a little notice on your obscure forum? Seriously?

WOW! Unbelievable.

My business? You shut down my business email, you nit.

Unbelievable.
abrams is offline  
Old 09-22-2016, 07:44 PM   Postid: 185380
jestaguy
Site Owner

Forum Notability:
0 pts: Even-handed
[Post Feedback]
 
Join Date: Apr 2007
Posts: 26
Re: PCI Compliance - TLSv1.0 Encryption Support

Hi Terra,
I'm seeing an issue on Apple devices (both the Mac and IOS) using the stock email client. Can you provide a little guidance on the settings to get the client to work? With SSL enabled, the client cannot connect to the email server. Disabling SSL seems to work in receiving email but not for sending.

Any assistance would be great, thanks!
jestaguy is offline  
Old 09-22-2016, 07:49 PM   Postid: 185381
hobbes
Have you hugged a tiger today?
 
hobbes's Avatar

Forum Notability:
1363 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Mar 2000
Location: Third Sol Planet Posts: Far too many. Oh ok -
Posts: 2,887
Re: PCI Compliance - TLSv1.0 Encryption Support

jestaguy - SMTP (outbound) email server settings are separately configured in iPhone Mail. You would have to disable both, but for security reasons shouldn't. Quick searches show that iPhone Mail only support TLS 1.0; hopefully this is incorrect, otherwise I can't see how FQ could proceed ahead with this. Hopefully they'll provide some guidance...
hobbes is offline  
Old 09-22-2016, 07:53 PM   Postid: 185382
 Terra
CTO FutureQuest, Inc.
 
Terra's Avatar
 
Join Date: Jun 1998
Location: Z'ha'dum
Posts: 8,108
Re: PCI Compliance - TLSv1.0 Encryption Support

Abrams, couple things:
1) We post all work announcements and updates to the public forums, and we've done that since 1998... Given the critical nature of PCI scans, we moved forward to fix this as quickly as possible...
2) Which aspect has caused failure, the ApacheSSL or Email part of the TLSv1.0 deprecation?
3) If email, which protocol? POP3S, SMPTS, IMAPS

We are truly sorry that this has affected you directly, we never want to see fallout from a change such as this...

We are looking to see about deploying a temporary bandaid solution by putting up a TLSv1.0 capable service on a non-standard port... However, we have to double check to make sure the PCI compliance scans won't find it as I've seen some scan the entire TCP port range looking for listeners...

jestaguy: We did some checks and:
IOS >= 5
OSX >= 10.8
__________________
The FutureQuest Team
Terra is offline  
Old 09-22-2016, 07:54 PM   Postid: 185383
abrams
Site Owner

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Dec 2001
Posts: 12
Re: PCI Compliance - TLSv1.0 Encryption Support

I've been with futurequest since 2001. I've stayed because of the exceptional customer service and uptime. Clearly something has changed. The original futurequest would NEVER do something like this without notice, several notices in fact.
abrams is offline  
Old 09-22-2016, 07:55 PM   Postid: 185384
 Terra
CTO FutureQuest, Inc.
 
Terra's Avatar
 
Join Date: Jun 1998
Location: Z'ha'dum
Posts: 8,108
Re: PCI Compliance - TLSv1.0 Encryption Support

Hobbes, we are between a rock and a hard place:
clients <=> FQ <=> PCI

and we got squeezed to make this change quickly due to the nature of ecommerce sites...

We are open to suggestions on how to solve this for both the clients and PCI compliance...
__________________
The FutureQuest Team
Terra is offline  
Old 09-22-2016, 07:59 PM   Postid: 185385
abrams
Site Owner

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Dec 2001
Posts: 12
Re: PCI Compliance - TLSv1.0 Encryption Support

Terra,

I'm using POP email because that is what you/futurequest told me to use? I have the same issue as jestaguy, only my desktop thunderbird email.
abrams is offline  
Old 09-22-2016, 07:59 PM   Postid: 185386
hobbes
Have you hugged a tiger today?
 
hobbes's Avatar

Forum Notability:
1363 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Mar 2000
Location: Third Sol Planet Posts: Far too many. Oh ok -
Posts: 2,887
Re: PCI Compliance - TLSv1.0 Encryption Support

For now, TLS 1.0 HAS to be re-enabled for email until the situation is resolved. Leave it off for HTTPS as browsers appear to have better support.

I have to agree that having no heads up was a bummer. I spent 30 minutes troubleshooting before finally realizing it had to be a change at FQ. I checked the forums but didn't see anything at first so figured it had to be on my end.

iPhone Mail appears hopeless thus far. Hopefully someone else has a solution for that.

For Outlook, I tried the following to no avail. I'm running Outlook 2016 on Win7 and would welcome suggestions.
https://blogs.technet.microsoft.com/...-on-windows-7/
hobbes is offline  


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:26 AM.


Running on vBulletin®
Copyright © 2000 - 2019, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2019 FutureQuest, Inc.
FutureQuest, Inc.