Light Patch Tuesday will include new encryption rule

Powered by SC Magazine
 

Next week's monthly patch batch from Microsoft is not very burdensome, but it includes a new requirement that certificates must contain RSA key lengths of more than 1,024 bits.

Microsoft is giving IT administrators a break next week, with the software giant only planning to release two patches to remedy four vulnerabilities.

Each of the bulletins, to be distributed Tuesday afternoon EST, is rated "important," meaning they do not meet Microsoft's highest-severity designation of "critical," and address issues in Visual Studio Team Foundation Server and System Center Configuration Manager.

The big news out of next week's automatic update is that it will include new requirements that users must employ certificates carrying an RSA key length of at least 1,204 bits. Customers actually are encouraged to run certs with much higher key lengths, even beyond 2,048 bits.

This is an additional safeguard that the software giant is releasing as a result of the Flame virus, which spread by spoofing Microsoft certificates.

"Though many have already moved away from such certificates, customers will want to take advantage of September's quiet bulletin cycle to review their asset inventories -- in particular, examining those systems and applications that have been tucked away to collect dust and cobwebs because they 'still work' and have not had any cause for review for some time," wrote Angela Gunn of Microsoft Trustworthy Computing in a Thursday blog post.

She acknowledged that customers should be prepared for a number of known kinks, including error messages or other difficulties, when applying the key length update.

Andrew Storms, director of security operations for vulnerability management vendor nCircle, said administrators must take this update seriously.

"This means older, legacy systems that rely on weak encryption or keys that are too short will stop working," he said in prepared email comments sent to SCMagazine.com. "Fix ‘em now, or be seriously sorry when they stop working in October.”

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Light Patch Tuesday will include new encryption rule
 
 
 
Top Stories
Australia's digital crescendo
Barely unpacked from his move from Amsterdam, Southern Cross Austereo's new digital boss Vijay Solanki is looking for Australia's untapped potential.
 
Turnbull nabs UK govt digital guru as DTO chief
Inaugural CEO to lead change agenda.
 
NBN to offer TV connections through fibre for greenfields
Ditching aerials to come at a cost.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Windows 10 drops 29 July... but only for some
Jul 6, 2015
If you've reserved your copy of Windows 10 and are keenly awaiting its 29 July release, don't ...
Xerocon is heading to Melbourne!
Jul 1, 2015
We're not saying Xero is our FAVOURITE or anything, but Xero's 2015 Xerocon conference is being ...
New Microsoft Office apps for Android phones
Jun 26, 2015
Microsoft's latest Office apps for Android now work on phones as well as tablets, further ...
Windows 10 UK price revealed, but don't believe everything you hear
Jun 26, 2015
Windows 10 £99 price tag for users in the UK (who presumably don't already have Win 7 Pro ...
Now Xero notifies iOS users of new transactions
Jun 24, 2015
The latest version of Xero's iPhone app includes notifications when new transactions arrive from ...
Latest Comments
Polls
Is site blocking effective in stopping piracy?


   |   View results
Yes
  2%
 
No
  86%
 
Somewhat
  12%
TOTAL VOTES: 806

Vote