12-17-2019 01:00 PM
I haven't been able to find any details on when/how Cisco will support TLS 1.3 on the email security devices. Any links you can share?
Thank you,
Jason
Solved! Go to Solution.
12-20-2019 01:00 PM - edited 08-02-2021 03:13 PM
Hello all,
Please note timelines may change if circumstances come up to affect it, but at the moment of this email - it is on the product teams roadmap as an item for implementation - however there are no commit dates that can be provided at this stage.
Regards,
Mathew
12-17-2019 01:15 PM
When i was looking for WSA/ESA , it was not supported and it was still in Draft, I have not checked recently 12.X might have support.
12-17-2019 01:19 PM
12-17-2019 01:40 PM
12-17-2019 01:38 PM
12-18-2019 11:29 AM
and just checking traffic last 30 days, we got ) TLS v1.3 messages so far, guess we have a bot of time
12-20-2019 01:00 PM - edited 08-02-2021 03:13 PM
Hello all,
Please note timelines may change if circumstances come up to affect it, but at the moment of this email - it is on the product teams roadmap as an item for implementation - however there are no commit dates that can be provided at this stage.
Regards,
Mathew
03-28-2021 04:04 AM
Hi Mathew,
The release notes of ESA 14 don´t show any information regarding TLSv1.3. Is support for TLSv1.3 pushed back to later versions of ESA?
Regards,
Paddy
05-22-2023 01:19 AM
It is 2023, five years after the release of the standard, and a "security" appliance cannot do TLS 1.3. An indictment, no one has to wonder why such products are often called snake oil.
A growing number of mail servers only support TLS 1.3 for encryption, which with an ESA means that these connections are only established unencrypted, or not at all if enforced.
Our goal is to only accept encrypted SMTP connections, but with the ESA this seems utopian due to the lack of support for modern cryptography. You pay several thousand Euros a year for this product and in the end you have to put an open source system in front of it as a smarthost to be state of the art and therefore compatible to other organizations.
05-22-2023 04:24 PM
Hello Ikgs,
I understand the sentiment, this has been a feature I've been advocating in terms of getting implemented into the environment as we want to continue to improve in the security space.
As at this moment, TLS1.3 is slated to be made available on our Cloud Secure Email Gateway (CES) environment first in the Cloud only release of 15.3 due later this year. The On-prem and Virtual ESA environments will see it in the following build there after.
In terms of exact time-lines, I am unable to share as different circumstances may arise with it, however its tentatively looking to be Q3 CY2023 (Subject to change if any critical concerns arise).
Thanks,
Mathew
05-04-2021 07:44 AM
There is an enhancement request filed for TLSv1.3 here:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf81830
Its status is still marked "Open" as of the current moment. Would suggest to subscribe for any changes regarding it.
05-04-2021 08:13 AM
Thanks. I subscribed.
Do you happen to know where I can find additional information regarding a timeline for TLSv1.3? The release notes of AsyncOS 14 don't offer any clue. All that I found (using: https://www.cisco.com/c/dam/en/us/td/docs/security/esa/esa14-0/Open_Source_Used_in_AsyncOS_14-0_for_Cisco_Secure_Email_Gateway.pdf) is that this version ships with openssl 1.0.2r (as a maximum version) and that for TLSv1.3 to be supported a minumum version of 1.1.1 is needed.
05-04-2021 08:28 AM
Unfortunately, cannot share any timelines or roadmaps for future releases of AsyncOS.
08-02-2021 01:22 AM
It's mid year 2021 and still no TLS 1.3 support? no date? no plans? really?
08-02-2021 03:15 PM
Hello Sascha,
I don't have an available date to share at this stage - however I can see internally it is on the roadmap for implementation. Once we have confirmation of a commit date; I will strive to share more details. At the moment it is on the agenda just cannot share when at this point.
Thank you,
Mathew
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide