As TLS 1.3 has reached final RFC status without interception possibilities: How will Sophos UTM protect against Web-Ads or Downloads which contain viruses ?
This thread was automatically locked due to age.
As TLS 1.3 has reached final RFC status without interception possibilities: How will Sophos UTM protect against Web-Ads or Downloads which contain viruses ?
Of course, you have to be using decrypt-and-scan for this to be done at all. With it enabled, UTM acts as server to the browser, and acts as client to the website. In both cases, it will negotiate based on what it can do, which will result in a TLS1.2 session. So there is no security breach created by its existence. I think we are a long ways from seeing either clients or servers that support TLS1.3 exclusively, so I do not think you will see denial-of-service for that reason.
I had read previously that TLS 1.3 created feasibility problems for decrypt-and-scan (https inspection). Your post caused me to research the issue further. The following links (all https) were helpful. I have obscured them with spaces because I don't think the forum allows links to non-Sophos sites (for our security).
Given all of that, I can understand why Sophos is not rushing to implement TLS 1.3 in UTM.
Of course, you have to be using decrypt-and-scan for this to be done at all. With it enabled, UTM acts as server to the browser, and acts as client to the website. In both cases, it will negotiate based on what it can do, which will result in a TLS1.2 session. So there is no security breach created by its existence. I think we are a long ways from seeing either clients or servers that support TLS1.3 exclusively, so I do not think you will see denial-of-service for that reason.
I had read previously that TLS 1.3 created feasibility problems for decrypt-and-scan (https inspection). Your post caused me to research the issue further. The following links (all https) were helpful. I have obscured them with spaces because I don't think the forum allows links to non-Sophos sites (for our security).
Given all of that, I can understand why Sophos is not rushing to implement TLS 1.3 in UTM.