Differences
This shows you the differences between the selected revisions of the page.
2023-10-09 | 2024-01-18 | ||
6.2 Change: SSL (3.0) is no longer supported. TLS 1.0 and 1.1 are disabled by default, to match the OpenSSL 3 defaults (martin) | no ssl + s3 also allows encryption configuration now (martin) | ||
Line 1: | Line 1: | ||
====== The TLS/SSL Page (Advanced Site Settings Dialog) ====== | ====== The TLS/SSL Page (Advanced Site Settings Dialog) ====== | ||
- | The //%%TLS/SSL%% page// on the [[ui_login_advanced|Advanced Site Settings dialog]] allows you to configure options of [[tls|TLS/SSL protocols]] for [[ftps|FTPS]], [[webdav|WebDAVS]] and [[s3|S3]]. | + | The //%%TLS/SSL%% page// on the [[ui_login_advanced|Advanced Site Settings dialog]] allows you to configure options of [[tls|TLS protocol]] for [[ftps|FTPS]], [[webdav|WebDAVS]] and [[s3|S3]]. |
&screenshotpict(login_tls) | &screenshotpict(login_tls) | ||
- | To reveal this page you need to select FTP or WebDAV file protocol and enable //Encryption// on [[ui_login|Login dialog]] or select S3 protocol. | + | To reveal this page you need to select FTP, WebDAV or S3 file protocol and enable //Encryption// on [[ui_login|Login dialog]]. |
&toc_title_page_sections | &toc_title_page_sections | ||
- | ===== TLS/SSL Options ===== | + | ===== TLS Options ===== |
- | Using //Minimum// and //Maximum %%TLS/SSL%% version// selections, you can configure what versions of TLS is WinSCP allowed to use. | + | Using //Minimum// and //Maximum %%TLS%% version// selections, you can configure what versions of TLS is WinSCP allowed to use. |
The %%TLS%% 1.0 and 1.1 are disabled by default, //in the latest beta version,// &beta to protect you from their known serious vulnerabilities. Enable them only, if the server does not support newer versions. You may want to restrict minimum %%TLS%% version further, in order to prevent WinSCP from using versions of %%TLS%% protocol that may become weak or insecure in the future. //The latest beta version does not support insecure SSL protocol of any version.// &beta | The %%TLS%% 1.0 and 1.1 are disabled by default, //in the latest beta version,// &beta to protect you from their known serious vulnerabilities. Enable them only, if the server does not support newer versions. You may want to restrict minimum %%TLS%% version further, in order to prevent WinSCP from using versions of %%TLS%% protocol that may become weak or insecure in the future. //The latest beta version does not support insecure SSL protocol of any version.// &beta | ||
Line 16: | Line 16: | ||
You may want to restrict maximum %%TLS%% version, when there is an interoperability problem with your server. Particularly %%TLS%% 1.3 is new and some servers do not implement it correctly. | You may want to restrict maximum %%TLS%% version, when there is an interoperability problem with your server. Particularly %%TLS%% 1.3 is new and some servers do not implement it correctly. | ||
- | Uncheck //Reuse %%TLS/SSL%% session ID for data connections//, when there is an interoperability problem with your FTPS server when reusing the %%TLS%% session ID. The option is available for FTP protocol only. | + | Uncheck //Reuse %%TLS%% session ID for data connections//, when there is an interoperability problem with your FTPS server when reusing the %%TLS%% session ID. The option is available for FTP protocol only. |
===== [[authentication]] Authentication parameters ===== | ===== [[authentication]] Authentication parameters ===== |