As of 30 June 2018, TLS 1.0 has been discontinued for PCI (Payment Card Industry Data Security Standard) environments. |
Initial situation:
To increase the security level of the SEPPmail Secure E-Mail Gateway, TLS 1.0 is to be deactivated.
Solution:
TLS 1.0 as well as other protocols and procedures which are only recommended with restrictions for security reasons (please also refer to Ciphers) are to be deactivated on the SEPPmail Secure E-Mail Gateway by activating the option
Disallow insecure ciphers (breaks compatibility with older browsers, but necessary for PCI compliance)
(see GINA Domains Settings).