Is Domino really still missing support TLS 1.3?

Hi team.

Hope you're all doing great.

Just upgraded to Domino 14 FP3 and noticed TLS 1.3 is still not supported.

Am I missing something or is it indeed accurate that it is currently not supported (yet)?

There's no update here:

HCL Notes/Domino - TLS 1.3 - Community

There's no update here:

TLS 1.3 Support for the Domino INET Stack | HCL Domino Ideas Portal

Totally agree with one of the comments: Do we need more votes for a Security implementation on a robust-secure platform like Domino?

Is there any other technical reason why this may have not been delivered yet?

Regards,

Elvis

It's time this was done!! Voting should not be the deciding factor here!!

yes, TLS 1.3 is currently not supported by any version of HCL Domino but as a workaround we can use HCL Safelinx in front of the Domino servers.

1 Like

Hi Sandeep. Thanks for your prompt response.

I understand it, but as mentioned on the given links, we should not rely or depend on third solutions, even from the same vendor, in order to achieve this.

One thing is Anti-Spam: It's completely understandable, as Domino mail is not aimed to be an Anti-Spam, however Domino supports querying to Black lists servers and other sources and we can always implement one in Gateway mode.

But, supporting an almost 7 years old protocol should be at core level already available.

Is there any technical reason why this may have not been delivered yet?

Regards,

Elvis.

Hello Elvis, don't know any technical reason but somewhere I read that TLS 1.3 overhauls SSL/TLS in the way that TLS 1.0 should have and it is under consideration for inclusion in a future release of Notes/Domino.

Despite being the latest version, TLS 1.3 is not universally adopted yet. Many websites still use TLS 1.2, but major platforms like Google and Facebook have implemented TLS 1.3. All modern browsers support TLS 1.3, but it may not be enabled by default in all operating systems, such as Windows 10.

We probably have to wait for Windows 12 for the client side ;-)))

I spoke to the Product manager for Domino, and he explained it's quite a difficult subject. They ARE working on it. The request status (see https://domino-ideas.hcltechsw.com/ideas/DOMINO-I-124 ) has changed from Planning to Implement, which usually means the feature will be available in the near future.