Planned Deprecation of Obsolete TLS Cipher Suites
Scheduled Maintenance Report for Pantheon Operations
Completed
The scheduled maintenance has been completed.
Posted Jun 08, 2023 - 10:01 PDT
In progress
Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted Jun 08, 2023 - 09:00 PDT
Scheduled
Obsolete cipher suites for TLS 1.2 will be removed on June 26th, 2023. In Pantheon's continual efforts to stay up to date with modern web security standards, we are planning on deprecating specific, obsolete ciphers. These cipher suites have been flagged by our InfoSec team as causing potential security risks that could impact the security of sites hosted on our platform.

Leading up to deprecation we will have a series of scheduled outages with the following timeline to see if you are affected:

June 8th, 2023 - Scheduled cipher suite removal for 1 hour (12 pm EDT)
June 22, 2023- Scheduled cipher suite removal for 24 hours (start at 12 pm EDT)
June 26th, 2023 - Cipher suites permanently removed (12 pm EDT)

The majority of modern browsers and platforms have removed support for these cipher suites as well. Even if any modern browsers or platforms support these weak ciphers, if the server (Pantheon Platform) does not support these, the TLS connections should be made on alternative strong cipher suites as part of the TLS connection process, and traffic will not be impacted. The majority of browser traffic is on TLS 1.3 and will not be affected. This will primarily affect incoming connections from out of date APIs or servers running out of date software.

The following obsolete TLS 1.2 ciphers will be removed:

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_128_GCM_SHA256
TLS_RSA_WITH_AES_256_CBC_SHA

Pantheon will be proactively identifying and communicating with affected customers. No action is required of you at this time, but if you have any questions/concerns, please feel free to reach out to your Account Team at Pantheon or to Pantheon Support via a ticket or chat.
Posted May 11, 2023 - 09:48 PDT
This scheduled maintenance affected: Global CDN.