Session

TLS Changed but Nobody Told Windows

Most of what admins learned about configuring SSL over the past twenty years is now wrong. The cipher suite lists you tuned, the registry keys you flipped, the protocol versions you fought to keep alive for that one old client. It's not even called SSL anymore. TLS 1.3 threw out nearly all of it, forced by twenty years of attacks and exploits.

This session tells that story. We start with how the TLS handshake actually works and what a certificate does inside it. Then we walk the timeline of attacks that broke it, one by one. BEAST, POODLE, FREAK, and Logjam each killed something you were still configuring, and most Windows environments never got updated.

Then we'll audit what your servers actually negotiate with PowerShell, fixing Schannel configuration, deciding which tweaks still matter, and retiring old protocol versions without breaking the clients you forgot about.

Todd Gardner

I start things.

Lake Elmo, Minnesota, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top