EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:31 PM . Last Modified: 2024-04-04 12:50 AM
We have been advised by Microsoft that support for sending email via Office 365 using TLS1.0 and TLS1.1 will be deprecated on 31st October. TLS1.2 must be used after this.
DCE appears to be using TLS1.0 and I can't see anywhere on DCE how to change the email to use TLS1.2.
Is this possible on DCE?
See
(CID:134681306)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
Hi Gary,
Starting with 7.5, DCE has an option to enable and disable different versions of TLS.
I am not 100% sure this also enables and disables these versions for e-mail communications but if the customer is testing this, simply have them disable the unwanted protocols. If they're not testing, let me know and I'll ask about it but it may take a little longer that way.
Steve
(CID:134681335)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
Hi Gary,
Starting with 7.5, DCE has an option to enable and disable different versions of TLS.
I am not 100% sure this also enables and disables these versions for e-mail communications but if the customer is testing this, simply have them disable the unwanted protocols. If they're not testing, let me know and I'll ask about it but it may take a little longer that way.
Steve
(CID:134681335)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
Those settings seem to relate only to how the DCE server itself is accessed and not how the email is sent from the server.
We disabled all but TLS1.2 on the settings you show in the image...
(CID:134681347)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
Thanks, That's what I 1/2 expected but just to be clear, you changed those settings and it's still trying to reach out via email with 1.0? Do you have packet captures or logs showing this so I can properly escalate to engineering?
(CID:134681370)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
Exactly that. I will ask the IT chap for the information that shows it is TLS1.0 tomorrow.
(CID:134681377)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
The MS 365 Admin centre shows the following...
I also have a slight more detailed log for 2 more emails but would rather not put them on a public forum.
Regards
(CID:134682296)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
Thanks Garry,
I'd already sent this to engineering but glad to get your screenshot...I attached it to the issue that I raised.
Problem I see is that since we can apparently not change it using the functionality that I mentioned (I assume you changed that setting before sending that e-mail) it will likely require an update of some sort. Assuming they take action, I can't promise this will be done by December. This could cause issues for you and the rest of the customers that use the SSL functionality in e-mail. I've raised that point to engineering as well.
Thanks,
Steve.
(CID:134682424)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
OK thanks for the response.
(CID:134682621)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:32 PM . Last Modified: 2024-04-04 12:50 AM
Hello Garry, is the customers server configured to require 1.2 as of now, or does the server still allow for 1.0? Our understanding is that DCE should negotiate the protocol, so if the server is only allowing 1.2 then DCE should use 1.2, if 1.0 is allowed then DCE would use 1.0. We're going to try and test this ourselves to confirm but would be interested to know if the customers SMTP server currently allows for TLS 1.0, which may be why DCE is sending using 1.0.
(CID:134682658)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:33 PM . Last Modified: 2024-04-04 12:50 AM
Hello Garry, could you confirm if the customers email server is set for TLS 1.2 and DCE is still trying 1.0 but then not trying 1.1 or 1.2? Our understanding is that DCE should work at 1.0 but if blocked will try 1.1, if blocked will try 1.2. Please confirm if this is the case.
(CID:134688990)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:33 PM . Last Modified: 2024-04-04 12:50 AM
Hi - the email service is provided by Microsoft (Office 365) and is currently supporting TLS1.0. MS advised that at the end of this month TLS1.0/1.1 will not be supported any more.
We don't seem to be able to choose to use TLS1.2 by default so cannot test the theory you propose. I was trying to make sure that we don't have multiple customers who have email that does not work at the end of the month, but I don't have the resources to test it.
Based on what you are saying it should not be a problem.
I hope not...
(CID:134689335)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:33 PM . Last Modified: 2024-04-04 12:50 AM
Hello Garry, correct, we believe that this should not be a problem but were hoping you could confirm this. We were trying to confirm this internally but wanted to see if actual external customers could confirm as well, since field data would be very helpful in this case.
Thanks.
(CID:134689593)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:33 PM . Last Modified: 2024-04-04 12:49 AM
Hi Garry,
Are you OK with Josh's comments? Is it working OK for you?
Steve
(CID:137105215)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 12:33 PM . Last Modified: 2023-10-22 01:24 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.