Google Chrome TLS v1.2 issue
Posted: Wed Apr 29, 2015 8:24 am
I am not sure that this is an AC issue, but when testing most of the websites listed under the featured websites on the main AbleCommerce site we found the same issue arising. It may be a coincidence, but either way hopefully someone can point us in the right direction.
Here is the issue:
Suddenly on Friday we started getting a few reports about the inability to access our https pages. Non SSL pages were fine- it was specifically when people tried to go to a secure page, such as the login page. We found a common denominator- all of these people were using Chrome. If they tried a different browser (IE, Firefox) they had no problems accessing the secure pages. We tried accessing the secure pages using Chrome on five different computers, from three locations, and none had any problem.
One of these customers found information that it was supposedly caused by a Microsoft update that messed something up with Chrome and TLS 1.2. By forcing Chrome to run at a maximum of TLS 1.1 she was able to access the secure pages. Our server is configured to run TLS 1.2, and when we check the SSL level when accessing the secure pages using IE or Firefox it shows the encryption to be TLS, 256 bit. However, on those computers that we were able to access the secure pages using Chrome, it is connecting using TLS 1.1 (the connection properties show a problem, and say that the connection had to be retried at TLS 1.1). This further confirms a problem with Chrome at TLS 1.2.
I then tried forcing Chrome on one machine to run at a minimum of TLS 1.2. Voila- I could replicate the issue when trying to go to one of our secure pages. Having something to go on I started trying to access secure pages on many of the AC's featured sites, and hit the exact same issue- you can go to non-secure pages, but not secure pages.
With Chrome forcing TLS 1.2 we CAN access secure pages on some other sites (Facebook, competitors sites that do not use AbleCommerce). The one site that I am pretty sure used AbleCommerce and I was able to access the secure pages is www.ablemods.com. The only thing that I could see different on this site is that it is running 128-bit security while we run 256-bit. I am not sure if this is the root of the problems, or if Joe has a patch installed on Able or his server (Joe- can you weigh in?).
Does anyone have any input? Because it is affecting so many AC sites I am guessing that this is related to AbleCommerce, or is a big coincidence (which I am not dismissing as a very real possibility). However, if it is just a coincidence, then we still need to find the problem and share it on here, as it is affecting a large number of AC websites, so there are obviously a number of people who need to employ some sort of fix to allow Chrome users to access their sites at TLS v1.2.
Here is the issue:
Suddenly on Friday we started getting a few reports about the inability to access our https pages. Non SSL pages were fine- it was specifically when people tried to go to a secure page, such as the login page. We found a common denominator- all of these people were using Chrome. If they tried a different browser (IE, Firefox) they had no problems accessing the secure pages. We tried accessing the secure pages using Chrome on five different computers, from three locations, and none had any problem.
One of these customers found information that it was supposedly caused by a Microsoft update that messed something up with Chrome and TLS 1.2. By forcing Chrome to run at a maximum of TLS 1.1 she was able to access the secure pages. Our server is configured to run TLS 1.2, and when we check the SSL level when accessing the secure pages using IE or Firefox it shows the encryption to be TLS, 256 bit. However, on those computers that we were able to access the secure pages using Chrome, it is connecting using TLS 1.1 (the connection properties show a problem, and say that the connection had to be retried at TLS 1.1). This further confirms a problem with Chrome at TLS 1.2.
I then tried forcing Chrome on one machine to run at a minimum of TLS 1.2. Voila- I could replicate the issue when trying to go to one of our secure pages. Having something to go on I started trying to access secure pages on many of the AC's featured sites, and hit the exact same issue- you can go to non-secure pages, but not secure pages.
With Chrome forcing TLS 1.2 we CAN access secure pages on some other sites (Facebook, competitors sites that do not use AbleCommerce). The one site that I am pretty sure used AbleCommerce and I was able to access the secure pages is www.ablemods.com. The only thing that I could see different on this site is that it is running 128-bit security while we run 256-bit. I am not sure if this is the root of the problems, or if Joe has a patch installed on Able or his server (Joe- can you weigh in?).
Does anyone have any input? Because it is affecting so many AC sites I am guessing that this is related to AbleCommerce, or is a big coincidence (which I am not dismissing as a very real possibility). However, if it is just a coincidence, then we still need to find the problem and share it on here, as it is affecting a large number of AC websites, so there are obviously a number of people who need to employ some sort of fix to allow Chrome users to access their sites at TLS v1.2.