Security

Voltar para Security Alert

Disabling TLS 1.0 for Inbound Traffic on Liferay Services and Websites

Published: November 1, 2018

Affected Version(s)

  • Liferay Systems and Services (see list in the linked article below)
  • Liferay Digital Experience Platform 7.0
  • Liferay Digital Experience Platform 7.1
  • Liferay Portal 6.2 EE
  • Liferay Portal 6.1 EE
  • Liferay Marketplace portlet
  • Liferay deployments and any applications running on Java 7 or below

General information

Due to vulnerabilities in the Transport Layer Security 1.0, Liferay will be disabling TLS 1.0 for inbound secure connections on all systems and services on November 30th, to follow the current industry practices.

Mitigation

Please navigate to the Knowledge Base for list of affected Liferay systems and services, as well as mitigation instructions for deployments.

UPDATE (as of 11/30/18): This change has been delayed to occur on January 11, 2019. Please refer to this updated article for more information.

On this page