- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
01-29-2019 08:20 PM
72 enables downgrade protection, and to an extent, the damage was already done with the release of 70. 72 is simply taking things a small step further. To prepare yourself for this, simply upgrade to one of the following and you should be good to go.
01-29-2019 11:21 PM
Hi BPry,
Thanks for your reply.
I tested with my testbed : PA-5020 v8.0.13 with Chrome 72.
Here is test results.
chrome://flags/#tls13-variant ## default
chrome://flags/#enforce-tls13-downgrade ## default
-> I could access to the gmail
chrome://flags/#tls13-variant ## default
chrome://flags/#enforce-tls13-downgrade ## enabled
-> confirmed "ERR_TLS13_DOWNGRADE_DETECTED"
-> also confirmed I could access to the gmail after I upgrade into 8.0.14.
chrome://flags/#tls13-variant ## default
chrome://flags/#enforce-tls13-downgrade ## disabled
-> I could access to the gmail
Thus, I believe downgrade protection is not enabled in 72.
01-30-2019 06:54 AM
They may have gotten enough pushback from Enterprise users that they chose not to enable it by Default; I know the original plan was to do so in 72. Looking through the Chromium commits I'm not seeing anything about it being switched in 73 either, they actually disabled the KeyUpdate function due to bugs.
I wouldn't be suprised to see this goalpost keep getting pushed back to be honest.
01-30-2019 02:37 PM
Google pushed the full enforcement to Chrome version 73 (unless they push it again). They have enabled it in version 72 but only if you don't trust the CA.
The advisory has now been updated to reflect this new info:
01-30-2019 07:03 PM
Hi BPry, gwesson
Thank you for replies. I understood the situation.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!