Identifying Legacy TLS Connections
In order to help with identifying the connections using legacy TLS protocols (TLSv1.1, TLSv1.0 or older) we've introduced a feature to track each site's use of deprecated insecure TLS versions.
Flow Production Tracking administrators can follow the steps below to track insecure connections to their Flow Production Tracking site.
Logging Deprecated TLS Events On a Flow Production Tracking Site
Under Site Preferences > Security enable the logging of deprecated TLS events.
Create a new page to display the deprecated TLS connections.
Create a page filter to only display the insecure connection events.
Reviewing Legacy Connections
Once the page is created, you'll receive events like the example below whenever a connection is made using an insecure protocol.
Using the Who field and the details provided in the Meta Data field, site administrators should be able to identify the tools and work towards updating them to compliant versions of TLS.
Performance Considerations
When a site admin turns on the site pref to record insecure TLS usage in the Event Log, it could create a lot of Event Log entries if the site has heavy API use from insecure TLS clients. As a result, we recommend turning off this site preference until the majority of identified client scripts are updated.