Strict TLS 1.3 in chrome 72 or 73?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Strict TLS 1.3 in chrome 72 or 73?

L5 Sessionator

Hello Guys,

 

Which information is true?

Chrome 72(in topic) or Chrome 73(in article)?

 

chrome72.pngchrome73.png

5 REPLIES 5

Cyber Elite
Cyber Elite

@emr_1,

72 enables downgrade protection, and to an extent, the damage was already done with the release of 70. 72 is simply taking things a small step further. To prepare yourself for this, simply upgrade to one of the following and you should be good to go. 

  • PAN-OS 8.1 must be ≥ 8.1.4
  • PAN-OS 8.0 must be ≥ 8.0.14
  • PAN-OS 7.1 must be ≥ 7.1.21

L5 Sessionator

Hi BPry,

 

Thanks for your reply.

 

I tested with my testbed : PA-5020 v8.0.13 with Chrome 72.

Here is test results.

 

chrome://flags/#tls13-variant ## default
chrome://flags/#enforce-tls13-downgrade ## default
-> I could access to the gmail

 

chrome://flags/#tls13-variant ## default
chrome://flags/#enforce-tls13-downgrade ## enabled
-> confirmed "ERR_TLS13_DOWNGRADE_DETECTED"

-> also confirmed I could access to the gmail after I upgrade into 8.0.14.

 

chrome://flags/#tls13-variant ## default
chrome://flags/#enforce-tls13-downgrade ## disabled
-> I could access to the gmail

 

Thus, I believe downgrade protection is not enabled in 72. 

@emr_1,

They may have gotten enough pushback from Enterprise users that they chose not to enable it by Default; I know the original plan was to do so in 72. Looking through the Chromium commits I'm not seeing anything about it being switched in 73 either, they actually disabled the KeyUpdate function due to bugs. 

 

I wouldn't be suprised to see this goalpost keep getting pushed back to be honest. 

Google pushed the full enforcement to Chrome version 73 (unless they push it again). They have enabled it in version 72 but only if you don't trust the CA.

 

The advisory has now been updated to reflect this new info:

https://live.paloaltonetworks.com/t5/Customer-Advisories/Action-required-if-you-have-enabled-SSL-dec...

 

Hi BPry, gwesson

 

Thank you for replies. I understood the situation.

  • 9133 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!