× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Announcements

Polls
What is your Experience with NETGEAR Insight cloud management?
Top Contributors

TLS v1.2 support for M4100-50G-POE+

Please add TLS v1.2 support to the M4100-50G-POE+ switch.  The lastest firmware version available for this product is 10.0.2.35 which does not include TLS v1.2 support.

3 Comments
gier
Fledgling

No current browser supports TLS 1, so HTTPS cannot be used. This is a serious security vulnerability that must be fixed as soon as possible. Please add TLS v1.2 support to the M4100 switches!

schumaku
Guru

@gier wrote:

No current browser supports TLS 1, so HTTPS cannot be used.


Not true, but not very secure either. This is why for example Apple, Google, and Opera (just to mention a few) have removed it from their default browser implementation:

 

Mozilla Firefox supports TLS 1.0, 1.1, and 1.2 by default. You shouldn't need to make any changes, but you can double-check the settings here if you like:

(1) In a new tab, type or paste about:config in the address bar and press Enter/Return. Click the button promising to be careful.

(2) In the search box above the list, type or paste TLS and pause while the list is filtered

(3) If the security.tls.version.max preference is bolded and "user set" to a value other than 3, right-click > Reset the preference to restore the default value of 3

(4) If the security.tls.version.min preference is bolded and "user set" to a value other than 1, right-click > Reset the preference to restore the default value of 1

The values for these preferences mean:

1 => TLS 1.0 2 => TLS 1.1 3 => TLS 1.2

gier
Fledgling

Thanks for the tips.

Default settings in FF 118.0.2 on Windows 10 are:

  • security.tls.version.enable-deprecated false
  • security.tls.version.fallback-limit 4
  • security.tls.version.max 4
  • security.tls.version.min 3

Apart from that: Why should I have to use a certain browser, whose security settings I have to change, to securely access a device that I bought a few years ago for over 2000 Euros?