Quantcast
Channel: SCN: Message List - SAP Single Sign-On
Viewing all articles
Browse latest Browse all 2732

Re: TLS_FALLBACK_SCSV (server-side)

$
0
0

Rob,

 

Which part of the word "secure service option" in the requirements for service providers in the official PCI-DSS 3.2 spec, Requirement A2.3 is unclear to you?

 

What you allege would need wording such as "secure-only service mandate" -- which clearly is *NOT* what the PCI-DSS spec says.

 

Btw. this discussion is about the TLS_FALLBACK_SCSV, which is completely irrelevant in the face of PCI-DSS discussions, because it is clearly impermissible for a PCI-DSS compliant client to perform a TLS protocol version downgrade dance at all, so this signaling cipher suite can *NOT* be used (and will never appear) in any PCI-DSS compliant communication.

 

-Martin


Viewing all articles
Browse latest Browse all 2732

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>