[upgrade] notice on upgrading OSS / DES / 3DES / HDFS / remote sensing image / MQ http / mqtt

[DAIZU] [micro message queue mqtt] [upgrade notice]

Upgrade window:

22:00, December 7, 2021 – 07:00, December 8, 2021, Beijing time

22:00, December 9, 2021 – 07:00, December 10, 2021, Beijing time

22:00, December 14, 2021 – 07:00, December 15, 2021, Beijing time

22:00, December 16, 2021 – 07:00, December 17, 2021, Beijing time

22:00, December 21, 2021 – 07:00, December 22, 2021, Beijing time

22:00, December 23, 2021 – 07:00, December 24, 2021, Beijing time

22:00, December 28, 2021 – 07:00, December 29, 2021, Beijing time

22:00, December 30, 2021 – 07:00, December 31, 2021, Beijing time

Upgrade content:

Mqtt services in all regions.

 

[DAIZU] [message queue MQ HTTP access] [upgrade notice]

Upgrade window:

22:30, December 1, 2021 – 05:00, December 2, 2021, Beijing time

22:30, December 6, 2021 – 05:00, December 7, 2021, Beijing time

22:30, December 8, 2021 – 05:00, December 9, 2021, Beijing time

22:30, December 15, 2021 – 05:00, December 16, 2021, Beijing time

22:30, December 20, 2021 – 05:00, December 21, 2021, Beijing time

22:30, December 27, 2021 – 05:00, December 28, 2021, Beijing time

Upgrade content: MQ services in all regions (HTTP access mode).

 

It is hereby notified that the satellite and UAV remote sensing image analysis products will be renamed “Digital Earth AI earth” from December 10, 2021.

 

For security reasons, the support of object storage OSS public cloud HTTPS for DES related encryption suites will be gradually removed from December 7, 2021.

 

Causes and effects:

The DES and triple des passwords used in TLS negotiation have a birthday circle of about four billion blocks, which can enable remote attackers to obtain plain text data through sweet32 attack.

At present, a small number of customers use the des related encryption suite in the process of using the object storage OSS HTTPS service. Due to the security risk of the suite in the TLS protocol, the object storage OSS plans to disable the 3DES and DES encryption suite. After disabling, the TLS connection business of the original customers through the des related encryption suite will not continue to be used. If the customer’s original business only supports des related encryption suites, please migrate to other encryption suites as soon as possible.

 

Remarks:

Please refer to cve-2016-2183 for information about DES algorithm

 

If you need to perform management operations on the console, please avoid the maintenance period. Please understand the inconvenience caused to you. If you have any questions, you can contact us through the work order at any time.

Related Posts

Contact US

Contact me

0451-81320128

Online consultation: QQ Conversation

Email: hi@dileetech.com

Working hours: 9:00-17:00, Monday to Friday, holidays.
wechat
Scan wechat and pay attention to us

Scan wechat and pay attention to us

micro-blog
Back to top