Beginning Tuesday, February 19th 2019 at 8am, our LDAP servers will no longer accept SSLv3 or TLSv1.0 connections. All clients must use TLS v1.1 or v1.2.
Please send any questions or problem reports to help@eecs.berkeley.edu.
UPDATE
[2019-02-19 11:05:37 | Rob McNicholas]
The IRIS LDAP servers behind ldap.eecs.berkeley.edu now only accept TLS 1.1 or 1.2 connections with strong ciphers. Here is a list of supported protocols and ciphers.
* tls1_1: AES256-SHA
* tls1_1: CAMELLIA256-SHA
* tls1_1: AES128-SHA
* tls1_1: SEED-SHA
* tls1_1: CAMELLIA128-SHA
* tls1_1: DES-CBC3-SHA
* tls1_1: IDEA-CBC-SHA
* tls1_1: RC4-SHA
* tls1_1: RC4-MD5
* tls1_2: AES256-GCM-SHA384
* tls1_2: AES256-SHA256
* tls1_2: AES256-SHA
* tls1_2: CAMELLIA256-SHA
* tls1_2: AES128-GCM-SHA256
* tls1_2: AES128-SHA256
* tls1_2: AES128-SHA
* tls1_2: SEED-SHA
* tls1_2: CAMELLIA128-SHA
* tls1_2: DES-CBC3-SHA
* tls1_2: IDEA-CBC-SHA
* tls1_2: RC4-SHA
* tls1_2: RC4-MD5
Resolved as of 2019-02-19 11:03:00