We have been trying to reach out to all our customers on our upcoming change to support for the SSL 3.0 encryption protocol.
We take security and the protection of our customers' data very seriously at Salesforce. Due to a recently published vulnerability with the SSL 3.0 protocol, we are phasing out support for it. Please review the link below and reach out to me if you have any questions on this change.
-------------
We want to inform you of a change regarding supported encryption protocols. Over the next two months, Salesforce will be disabling SSL 3.0 encryption in a phased approach to prevent it from being used to access the Salesforce platform.
Why is this happening?
At Salesforce, trust is our #1 value, and we take the protection of our customers' data very seriously.
On October 15, Google researchers published details on a security vulnerability (CVE-2014-3566) that affects the Secure Socket Layer (SSL) 3.0 encryption protocol, also known as “POODLE,” which may allow a man-in-the-middle attack to extract data from secure HTTP connections. Although the vulnerability is somewhat difficult to exploit, to further protect customers, we will be disabling SSL 3.0 to fully address this issue.