<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Sophos SEC 5.5.1 - won&amp;#39;t start if TLS 1.0 is disabled</title><link>https://community.sophos.com/on-premise-endpoint/f/sophos-enterprise-console/110913/sophos-sec-5-5-1---won-t-start-if-tls-1-0-is-disabled</link><description>Hi, 
 
 We upgraded our Sophos SEC instance from 5.5.0 to 5.5.1 to support TLS 1.2. The database is on dedicated SQL server which supports TLS 1.2. 
 
 When we disable TLS 1.0 (client/server) on the Sophos SEC server, the application cannot start. 
 </description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Sophos SEC 5.5.1 - won't start if TLS 1.0 is disabled</title><link>https://community.sophos.com/thread/446098?ContentTypeID=1</link><pubDate>Mon, 31 Aug 2020 12:56:13 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0bb45d73-2704-404f-8e3c-0d31592d8592</guid><dc:creator>Sean Davis</dc:creator><description>&lt;p&gt;This helped me, thanks.&amp;nbsp; But I found that the command fails unless I have explicitly enabled TLS 1.0.&amp;nbsp; With that enabled, I successfully ran the command and saw the message:&amp;nbsp; Encrypted connection to the SQL Server is established.&amp;nbsp; Now that the connection config has been updated, I disabled TLS 1.0&amp;nbsp;but subsequent start of SQL Server fails again.&amp;nbsp; So apparently, I have to leave 1.0 enabled in order for Sophos SQL to use 1.2...&lt;/p&gt;
&lt;p&gt;It&amp;#39;s great that Sophos will use TLS 1.2 but the point is to be able to disable TLS 1.0 and 1.1 altogether, right?&amp;nbsp; Am I missing something else because this improves security of Sophos while still leaving my server vulnerable to TLS 1.0&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos SEC 5.5.1 - won't start if TLS 1.0 is disabled</title><link>https://community.sophos.com/thread/397268?ContentTypeID=1</link><pubDate>Tue, 19 Feb 2019 16:39:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4999fee0-d0be-4b2f-816c-4f5674ff8d3f</guid><dc:creator>David Lewis1</dc:creator><description>&lt;p&gt;We were able to get the Sophos Enterprise Console to load with just TLS 1.2 enabled by doing the following:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;C:\sec_551\serverinstaller\checkdbconnection&amp;gt; .\CheckDBConnection.exe -s&amp;nbsp;&amp;lt;SQL Server&amp;gt;&amp;nbsp;-t onfce -c &amp;ndash;a &amp;nbsp;(This &amp;ndash;a flag tells the program to change the Db connection settings for Sophos).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hope this helps someone in the Interwebs.&lt;/p&gt;
&lt;p&gt;David&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>