Skip to main content

#TLS 1.0 Disablement0 utenti parlano di questo argomento

This is all about Admins preparing to manage their orgs before TLS 1.0 disablement : - what is it about ? - what needs to be done ? - what is the compliance status of AppExchange apps ? - checklists etc.

Dear Community,

we are using Maildrop and since the TLS 1.0 Disablement, we can not upload any Mails or connect them to our Clients. Is there any option to solve this problem and to continue using Maildrop?

Or can you recommend us another app/programm, which can be used on Mac/OS?

Thanks in advance.

6 commenti
  1. 2 gen 2018, 05:47
    As an update, I now have an updated version published at https://github.com/stevenlawrance/maildrop/releases/tag/v2.991

    .

    From evaluating the software, it looks like the older and current versions of Maildrop should work using TLS 1.2 automatically, provided that the version of Mac OS X being used is 10.9 (Mavericks) or newer. Indeed, the current 2.99 version as-is works for me using TLS 1.2 in my macOS 10.12 (Sierra) system. This newer version also works, and it addresses a couple attachment related issues.

    Are you running an older version of Mac OS X? If so, you'll need to upgrade it to 10.9 (Mavericks) or newer for TLS 1.1 or higher to get used.

0/9000

We pulled out an email log to verify the TLS Version used and we could see the "TLS_Cipher" & "TLS_Verified". Most of the transactions happened via the TLS1.2 except 3 or 4 which showed as ":" and all the transactions have TLS_Verified as "unverified". Will there be any impact because of the certificate not being verified? What are the steps we need to follow to get it verified. Request your inputs on this.

4 commenti
  1. 16 mar 2018, 03:10
    @Vinod Mummareddy Sincere apologies for missing your post ... From what I saw in your log, the messages delivered via TLS 1.0 were all delivered to hosts with IP address in 186.90.28.* ... it is possible that some of the MTAs for your domain support TLS1.1 and higher and some do not. You should speak with your Mail team. Please see the direct message I sent you as well ...
0/9000

#TLSemail 

#TLS 1.0 Disablement 

 

Hello,

 

We're continuing to receive the TLS Disablement email notification despite confirming that our email server uses a higher version (we use Gmail which uses TLS 1.2). Is there a reason we are continuing to receive these emails and notifications or some next steps we need to take? I'm concerned because the email states: "You are receiving this communication because you are the admin of a Salesforce org that is still either sending or receiving emails from your Salesforce org using the TLS 1.0 encryption protocol." and yet we only send outbound messages through our Gmail server which already meets the new standard. 

 

Please clarify. Thank you!

 

Sarah 

20 commenti
  1. 5 mar 2018, 20:58
    @Lyn Kelly

    I'll paste in some general responses to questions I have used over the last 2 months. The first paragrapgh below answers your question. Hope this helps.

    TLS 1.0

    First - as to why you received the email ... we are pulling a list every month of any orgs that are sending or receiving any email by TLS 1.0. Even if you have verified that your company's mail servers are using TLS 1.1 or higher, you could still show up on the list because one of your customers mail servers is still using TLS 1.0 and you sent mail to them or they sent mail to an email service that you own in Salesforce.

    Your main action should be to verify that your company'e mail servers are using TLS 1.1 or higher. If you have done that already - that's awesome. That is the main thing that is in your power to control. If you have not already done this verification, we have made 2 recent changes which will help you:

    1) For inbound mail to Salesforce, we now add a header that indicates the version of TLS used when the mail was sent to us - X-SFDC-TLS-VERSION. You can use the email capture facility as described in the original notifications to capture a mail sent from your service and verify the specific version of TLS used.

    2) For outbound mail, we recently put out a patch for the Spring 18 release that adds TLS version information to the Email Log access function available to Admins. Using that tool, you can pull information about mail that your organization has sent from Salesforce. It will show what version of TLS was used when delivering email.

    If your company's mail servers are good to go and the issue is with your customers that you are communicating with - you are correct in that it is a bit out of your control. For outbound email, you can use the admin logs to see who is using TLS 1.0 and notify them that they should look into upgrading if you wish to do so . For Inbound mail, the notifying action is really up to the sending mail servers.

    What happens after we disable TLS 1.0 for email in salesforce?

    For outbound mail: the email will still be delivered even if we cannot negotiate TLS - it will just be delivered unencrypted. The only exception to this is if you activate TLS Required. You can continue to use the Admin Email Log access function to see what version of TLS is being used or if its not being used. .

    For Inbound mail - the action taken when TLS cannot be negotiated is really up to the sending mail server. They should either send it unencrypted, or the message should be bounced back to the sender so they will get notification.

    At this point in time, we have seen the use of TLS 1.0 continue to slowly decline. In our most recent review across all mail sent to/from Salesforce, the amount of mail sent from our servers using TLS 1.0 was less than 2% and the amount of mail being delivered to us using TLS 1.0 was less than 2.5 %.

0/9000

Hello All,

  My question related to the TLS 1.0 Disabling is:

 I have the functionality of the "email-to-case" working well right now, the way it works is, the customer send us an email (to our company email server), then, we have configured a redirection to our salesforce mail service email, so the case can be created automatically.

I had validated my company mail server, which have the TLS 1.2, so everything looks ok so far, my doubt is, what happen is the external customer have the TLS 1.0? the case can be created without issues? since the external email are going through our company mail server and the redirection email happens anyway to the salesforce mail service.

 

Or do you think that the external customer also must upgrade to TLS 1.1 + version?

 

Thanks in advance

#TLSemail #TLS #TLS 1.0 Disablement 

3 commenti
  1. 2 mar 2018, 21:41
    @Gerald Lizardo Matarranz sorry for the delay in response. On outbound mail from Salesforce, if we cannot negotiate TLS for any reason then we will still send the email but unencrypted (unless you configure your org to require TLS).
0/9000

We pulled out an email log to verify the TLS Version used and we could see the "TLS_Cipher" & "TLS_Verified". Most of the transactions happened via the TLS1.2 except 3 or 4 which showed as ":" and all the transactions have TLS_Verified as "unverified". Will there be any impact because of the certificate not being verified? What are the steps we need to follow to get it verified. Request your inputs on this.

0/9000

#TLSemail 

Hi,

we have been doing some tests and we found an issue that we not understand. 

 

We found a client that is sending to us emails in TLS 1.2 (we know this because the headers) but is not receiving emails when TLS is set as "Required", also we did the test Deliverability to the client and he didn't receiving none of the 32 emails... But when TLS is set as "Prefered" is receiving the 32 emails... 

 

So the conclusion is that we can't trust only see the headers of the incoming email... Am I wrong? Then now we don't know how many clients can be affected to this change... 

2 commenti
  1. 8 feb 2018, 07:20
    Hi @Lisa Mac

    , in March, 8 when you do the TLS change this customers are not going to receive any email, right?

    I will open the case anyways.

    Thanks!

0/9000

Hello all,

this question is regarding the TLS 1.0 deactivation for emails that is taking place on the 6th of March. 

According to the help article (https://help.salesforce.com/articleView?id=000268344&type=1) I will have to check the inbound and outbound Salesforce emails.

Is there a difference if I check the sandbox instance instead of the production one ? 

Thanks in advance!

 

Regards,

Silvia

3 commenti
0/9000

-- TLS 1.0 Disablement this Weekend --

The following instances will have TLS 1.0 disabled this Saturday, November 11, 2017, at 9:30am US Pacific Time:

 

AP1, AP4, AP5, NA24, NA30, NA49, NA50, NA56, NA59, NA61, NA62, NA99, CS2, CS4, CS5, CS6, CS8, CS14, CS31, CS41, CS43, CS44, CS57, CS58, CS64, CS65, CS98, CS99

 

If you have questions about this change please do not post them as comments on this post. Instead, please create a new post so your question can get the most visibility. We monitor on the Community daily. For the fastest answer, please search this community as your question may have already been answered. Thank you.

TLS 1.0 Disablement Schedule

0/9000

Hi, for TLS disablement, once I searched for Critical updates, a list appeared as shown in the webinar. It does not show 'Require TLS 1.1 or higher for HTTPS connections. What does this mean for my organization? #TLS 1.0 Disablement 

1 commento
  1. 5 ott 2017, 05:12
    Thanks for asking about that. That likely means that your org already has TLS 1.0 turned off. If the HTTPS connections to and from your org are working, then you're in a good state regarding the TLS 1.0 disablement.
0/9000

Hi can I please get the slide deck link for TSL 1.0 disablement? I have the link to the webinar already #TLS 1.0 Disablement 

1 commento
0/9000