TS-SRAN-SW-0160 End of TLS Protocol Version 1 0 and 1 1 Support

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 15

No further reproduction or networking is permitted. Distributed by Nokia.

Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.


TS-SRAN-SW-0160: End of TLS protocol
version 1.0 and 1.1 support
Radio Network

TS-SRAN-SW-0160
Issue 3.0 APPROVED
Approved on 2023-08-25

Single RAN Technical Support Notes Library

Maintenance Documentation, Issue 01

© 2023 Nokia. Nokia Condential Information. Use subject to agreed restrictions on disclosure and use.
No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
Nokia is committed to diversity and inclusion. We are continuously reviewing our customer
documentation and consulting with standards bodies to ensure that terminology is inclusive
and aligned with the industry. Our future customer documentation will be updated
accordingly.

This document includes Nokia proprietary and condential information, which may not be
distributed or disclosed to any third parties without the prior written consent of Nokia. This
document is intended for use by Nokia’s customers (“You”/”Your”) in connection with a
product purchased or licensed from any company within Nokia Group of Companies. Use this
document as agreed. You agree to notify Nokia of any errors you may nd in this document;
however, should you elect to use this document for any purpose(s) for which it is not
intended, You understand and warrant that any determinations You may make or actions
You may take will be based upon Your independent judgment and analysis of the content of
this document.

Nokia reserves the right to make changes to this document without notice. At all times, the
controlling version is the one available on Nokia’s site.

No part of this document may be modied.

NO WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO
ANY WARRANTY OF AVAILABILITY, ACCURACY, RELIABILITY, TITLE, NON-INFRINGEMENT,
MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, IS MADE IN RELATION TO THE
CONTENT OF THIS DOCUMENT. IN NO EVENT WILL NOKIA BE LIABLE FOR ANY DAMAGES,
INCLUDING BUT NOT LIMITED TO SPECIAL, DIRECT, INDIRECT, INCIDENTAL OR
CONSEQUENTIAL OR ANY LOSSES, SUCH AS BUT NOT LIMITED TO LOSS OF PROFIT,
REVENUE, BUSINESS INTERRUPTION, BUSINESS OPPORTUNITY OR DATA THAT MAY ARISE
FROM THE USE OF THIS DOCUMENT OR THE INFORMATION IN IT, EVEN IN THE CASE OF
ERRORS IN OR OMISSIONS FROM THIS DOCUMENT OR ITS CONTENT.

Copyright and trademark: Nokia is a registered trademark of Nokia Corporation. Other


product names mentioned in this document may be trademarks of their respective owners.

© 2023 Nokia.

2 © 2023 Nokia. Nokia confidential


No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
Table of Contents

1 Technical Note Information ........................................................................................................ 4

Summary of changes .................................................................................................................... 6

Contact ........................................................................................................................................... 7

2 Purpose .......................................................................................................................................... 8

3 Validity ............................................................................................................................................ 9
3.1 Impacted technology ........................................................................................................ 9
3.2 Impacted system and SW releases ................................................................................. 9
3.3 Impacted products ......................................................................................................... 10
3.4 Related parameters ........................................................................................................ 10
3.5 Related features ............................................................................................................. 10

4 Keywords ..................................................................................................................................... 12

5 Executive summary .................................................................................................................... 13

6 Impact on the network .............................................................................................................. 14

7 Detailed description .................................................................................................................. 15

© 2023 Nokia. Nokia confidential 3


No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
1. Technical Note Information

Technical Support Note

TS-SRAN-SW-0160

End of TLS protocol version 1.0 and 1.1 support

Radio Network

Radio Network Solutions

Single RAN (SBTS)

Approval date: 2023-08-25

This document contains following type of information

Informative

Preventive X

Corrective

Additional categorization

Urgent

Security X

Release Upgrade X

SW Update

Parametrization X

Information is classified as

Internal

4 © 2023 Nokia. Nokia confidential


Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
No further reproduction or networking is permitted. Distributed by Nokia.

5
X

© 2023 Nokia. Nokia confidential


Information is classified as

Customer Specific
All Customers
No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
Summary of changes

Date Version Change

2023-03-17 1.0 Approved version

2023-05-16 2.0 Validity for 23R3-SR has been


added.

2023-08-25 3.0 Validity for 23R4-SR has been


added.

6 © 2023 Nokia. Nokia confidential


Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
No further reproduction or networking is permitted. Distributed by Nokia.

7
© 2023 Nokia. Nokia confidential
Contact your local Nokia support.
Contact
No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
2. Purpose

This document contains generic information about products. These can be instructions that
explain problem situations in the field, instructions on how to prevent or how to recover from
problem situations, announcements about changes or preliminary information as requirements
for new features or releases.

8 © 2023 Nokia. Nokia confidential


No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
3. Validity

3.1 Impacted technology

Technology Impact

GSM/EDGE

WCDMA

Small Cells

Single RAN X

Nokia Core

Nokia Public Sector

Data Center and Cloud Infrastructure

5G

Wi-Fi

Factory Delivery SW

3.2 Impacted system and SW releases

Tip:
The presented validity information includes the currently active software. The section is re-
assessed prior to every new System Release availability.

© 2023 Nokia. Nokia confidential 9


No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
System Release Product SW Release(s)

22R2-SR 22R2-SR (SBTS): all product SW releases

22R3-SR 22R3-SR (SBTS): all product SW releases

22R4-SR 22R4-SR (SBTS): all product SW releases

23R1-SR 23R1-SR (SBTS): all product SW releases

23R2-SR 23R2-SR (SBTS): all product SW releases

23R3-SR 23R3-SR (SBTS): all product SW releases

23R4-SR 23R4-SR (SBTS): all product SW releases

3.3 Impacted products

Product

Single RAN (SBTS)

3.4 Related parameters

Parameter class Parameter long Parameter Parameter structure


(MOC) name abbreviated name name

MRBTS Enable TLS1.1 Support tls11Enabled

3.5 Related features

10 © 2023 Nokia. Nokia confidential


Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
No further reproduction or networking is permitted. Distributed by Nokia.

11
LTE OAM Transport Layer Security (TLS)

© 2023 Nokia. Nokia confidential


Feature name

Support
Feature ID

LTE150
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
No further reproduction or networking is permitted. Distributed by Nokia.

© 2023 Nokia. Nokia confidential


deprecated | TLS 1.0 | TLS 1.1
4. Keywords

12
No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
5. Executive summary

For Single RAN base stations the TLS 1.0/1.1 protocol and the associated ciphers will be removed
starting from Single RAN program 23R4-SR.

© 2023 Nokia. Nokia confidential 13


No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
6. Impact on the network

In case the operator makes use of own syslog servers or own Trace Collection Entity (TCE) servers
not provided by Nokia then the TLS secured communication with these servers will fail if the
servers only support TLS 1.0/1.1.

14 © 2023 Nokia. Nokia confidential


No further reproduction or networking is permitted. Distributed by Nokia.
Copyrighted material licensed to muhammad-adil.murad@450connect.de on 17-10-2023.
7. Detailed description

For Single RAN base stations, the TLS 1.0/1.1 protocol and the associated ciphers will be
deactivated starting from SRAN 23R4-SR.

The reasons behind this decision are:

The Internet Engineering Task Force has formally deprecated the TLS 1.0 and TLS 1.1
cryptographic protocols on the grounds of security after several attacks were discovered over
the past years that put encrypted internet communications relying on the two protocols at
risk.
The Transport Layer Security (TLS) 1.0 and 1.1 protocols are deprecated by 3GPP Rel 16 TS
33.210.

Before Single RAN 23R4-SR a Single RAN BTS supports TLS 1.2 and TLS 1.3 but TLS 1.0/1.1 can
be activated only on demand to overcome backward compatibility issues in case the operator
makes use of own syslog servers or own Trace Collection Entity (TCE) servers not provided by
Nokia and these servers are only supporting TLS 1.0/1.1.

Note:
There is no fallback to TLS 1.0/1.1 supported starting from 23R4.

To effectively end support of TLS 1.0/1.1 in Single RAN 23R4-SR and upcoming SRAN releases the
feature LTE150: LTE OAM Transport Layer Security (TLS) Support will be deactivated by
executing actions described below:

The MOCN parameter Enable TLS1.1 Support/tls11Enabled will be not available


anymore and also the run time parameter TLS1.1 enable state towards the
operation and maintenance system/tls11EnabledStatuswill be not available
anymore.
The following TLS ciphers will be not supported anymore:
TLS_DHE_RSA_WITH_AES_256_CBC_SHA (DH 2048)
TLS_RSA_WITH_AES_256_CBC_SHA (RSA 2048)
TLS_DHE_RSA_WITH_AES_128_CBC_SHA (DH 2048)

© 2023 Nokia. Nokia confidential 15

You might also like