KitKat and TLSv1.2

栏目: IT技术 · 发布时间: 5年前

内容简介:TLSv1.2 came out in 2008 but Android didn’t get support for it until Android 5 in 2014. Previous releases including Android 4.4 KitKat support up to TLSv1.1 by default.KitKat’s old TLSv1.1 isn’t secure enough and so its retirement has been planned for a lo

TLSv1.2 came out in 2008 but Android didn’t get support for it until Android 5 in 2014. Previous releases including Android 4.4 KitKat support up to TLSv1.1 by default.

KitKat’s old TLSv1.1 isn’t secure enough and so its retirement has been planned for a long time. RFC 7525 said this in 2015:

“Implementations MUST support TLS 1.2 and MUST prefer to negotiate TLS version 1.2 over earlier versions of TLS.
Rationale: Several stronger cipher suites are available only with TLS 1.2. In fact, the cipher suites recommended by this document are only available in TLS 1.2.”

Browsers are shutting off TLSv1.1 right now.

SSL Labs started limiting grades to ‘B’ for HTTPS sites that still offer TLSv1.1. Early this year Chrome , Safari , Firefox , and Edge will require TLSv1.2 or better.

Keep KitKat?

If you maintain an app that runs on KitKat, you have options:

  • Continue to use TLSv1.1.Webservers can support many versions of TLS simultaneously and so you can offer TLSv1.1 to KitKat users and TLSv1.2 to everyone else.

  • Hook up Google Play Services’ ProviderInstaller.This lets you run TLSv1.2 on KitKat devices that have Play Services set up. See Ankush Gupta’s guide for instructions .

  • Embed Conscrypt.You can include a copy of Conscrypt, a library from Google that integrates BoringSSL with Java. This adds about 3 MiB to your APK and you’ll need to remember to keep Conscrypt itself up-to-date. This StackOverflow answer describes what to do.

Code that targets KitKat is limited to OkHttp 3.12.x. Newer releases require Android 5 or newer !

Kill KitKat!

Android 5 came out in 2014. Devices like 2012’s Nexus 4 and 2013’s Galaxy S4 were updated to Android 5.

You could just stop shipping app updates to these dinosaurs and that will be okay. Just remember to keep TLSv1.1 enabled on your web servers.


以上就是本文的全部内容,希望本文的内容对大家的学习或者工作能带来一定的帮助,也希望大家多多支持 码农网

查看所有标签

猜你喜欢:

本站部分资源来源于网络,本站转载出于传递更多信息之目的,版权归原作者或者来源机构所有,如转载稿涉及版权问题,请联系我们

长尾理论

长尾理论

[美]克里斯•安德森 (Chris Anderson) / 乔江涛、石晓燕 / 中信出版社 / 2012 / 68.00元

网络经济正如火如荼地发展着,长尾理论无疑成为当代商务人士最为关注的焦点之一。不论是关于长尾理论的溢美还是论战,都代表了其备受关注的程度。 《长尾理论》是克里斯•安德森对这些争论的最明确的回答。在书中,他详细阐释了长尾的精华所在,指出商业和文化的未来不在于传统需求曲线上那个代表“畅销商品”的头部,而是那条代表“冷门商品”的经常被人遗忘的长尾。他还揭示了长尾现象是如何从工业资本主义原动力——规模......一起来看看 《长尾理论》 这本书的介绍吧!

JS 压缩/解压工具
JS 压缩/解压工具

在线压缩/解压 JS 代码

XML、JSON 在线转换
XML、JSON 在线转换

在线XML、JSON转换工具

HEX CMYK 转换工具
HEX CMYK 转换工具

HEX CMYK 互转工具