{"id":359952,"date":"2018-11-15T11:31:45","date_gmt":"2018-11-15T19:31:45","guid":{"rendered":"http:\/\/www.esri.com\/arcgis-blog\/?post_type=blog&#038;p=359952"},"modified":"2022-02-16T10:56:29","modified_gmt":"2022-02-16T18:56:29","slug":"2019-arcgis-transport-security-improvements","status":"publish","type":"blog","link":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements","title":{"rendered":"2019 ArcGIS Transport Security Improvements"},"author":3911,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"_acf_changed":false,"_searchwp_excluded":""},"categories":[37501],"tags":[24081,24071],"industry":[],"product":[763582],"class_list":["post-359952","blog","type-blog","status-publish","format-standard","hentry","category-administration","tag-ssamymlgp","tag-security","product-trust-arcgis"],"acf":{"short_description":"Significant transport security improvements in 2019 could result in disruption of operations if customer validation is not performed beforehand.","flexible_content":[{"acf_fc_layout":"content","content":"<p>To ensure our service and software offerings remain as secure as possible, we continually update the security standards and protocols utilized.\u00a0 Sometimes, <em>this can result in significant disruptions for customers<\/em> if they do not keep their client systems and configurations consuming SaaS offerings (such as ArcGIS Online) up-to-date.\u00a0 Throughout 2019, there are multiple such significant changes occurring that you should be aware of and prepare for before they are enabled.<\/p>\n<p><strong>April 2019 \u2013 ArcGIS Online TLS 1.0 &amp; 1.1 removal<\/strong><\/p>\n<p>ArcGIS Online currently supports TLS 1.0, 1.1, and 1.2, however on April 16, 2019 only TLS 1.2 will be available for clients to connect.\u00a0 The older protocol versions were published over a decade ago and many improvements have been made since their release, therefore TLS 1.2 is now considered the safest and most reliable method of delivering encrypted content over the Internet.<\/p>\n<p>Furthermore, the PCI Data Security Standard (PCI DSS) and the FedRAMP authorization program require disabling SSL\/TLS 1.0 implementations.\u00a0 TLS 1.1 will still be accepted by PCI and FedRAMP although they strongly recommend TLS 1.2.\u00a0 Given security concerns with both TLS 1.0 and 1.1 and the recommendations provided by multiple standards organizations, we are deprecating support of both versions moving forwards.<\/p>\n<p>Most users accessing ArcGIS Online via a browser should not need to do anything, as <a href=\"https:\/\/caniuse.com\/#search=TLS%201.2\">TLS 1.2 is compatible with all recent major browser versions<\/a>.\u00a0 Some ArcGIS Online clients, such as ArcGIS Pro, are already TLS 1.2 enabled.\u00a0 Esri software that requires action includes ArcGIS Desktop and applications built on and extending ArcGIS Desktop, ArcGIS Enterprise, applications built with ArcGIS Engine (ArcObjects), and partner extensions that access ArcGIS Online services.\u00a0 Go to the\u00a0<a href=\"https:\/\/support.esri.com\/en\/tls\">Esri TLS Support page<\/a>\u00a0for more information and specific actions you may need to take in advance of this update.<\/p>\n<p><strong>Upcoming ArcGIS Enterprise 10.7 \u2013 TLS 1.0, 1.1, and HTTP disabled by default<\/strong><\/p>\n<p>To help foster secure-by-default installations, only HTTPS with TLS 1.2 will be enabled for the upcoming ArcGIS Enterprise 10.7 release (ArcGIS Enterprise 10.6.1 defaults to disabling TLS 1.0, and previous versions default to using TLS 1.0, 1.1, 1.2, HTTP, and HTTPS).\u00a0 Note that performing an upgrade from a previous ArcGIS Enterprise version will not disable HTTP, TLS 1.0, or 1.1 (if they were enabled on the pre-existing deployment) to minimize disruption of customer operations \u2013 Customers performing an update can configure their ArcGIS Enterprise deployment to utilize only HTTPS and TLS 1.2 as documented in the online help.<\/p>\n<p><strong>Spring 2020\u2013 ArcGIS Online HTTP deprecation + HSTS enforcement<\/strong><\/p>\n<p>ArcGIS Online has always had an optional setting that allows organizations to require that all communication with their ArcGIS Online hosted organization &amp; services must be over HTTPS (ArcGIS Online organizations established after the September 2018 release no longer allow enabling HTTP).\u00a0 In addition, ArcGIS Online supports HTTPS based communication to all shared services such as geocoding, routing and basemaps.<\/p>\n<p>HTTP Strict Transport Security (HSTS) is a security enhancement that is specified by web applications through the use of a special response header.\u00a0\u00a0 Once a supported browser receives this header that browser will prevent any communications from being sent over HTTP to the specified domain. \u00a0It achieves this goal by automatically converting all plaintext links to secure ones. As a bonus, it also disables click-through certificate warnings.<\/p>\n<p>In 2017, we transparently enabled HSTS for ArcGIS Online organizations that utilize the default organization setting that forces HTTPS for all communications.\u00a0 This means that all customer data is afforded the additional protection HSTS provides by default.\u00a0 It is important to note that organizations executing security tests (such as SSLLabs) against their organization URL will likely still see results indicating that HSTS is not enabled.\u00a0 This happens because all ArcGIS Online organizations access a common set of static files (some orgs access via HTTP and others access via HTTPS) and it is the accessing of the static files (not customer data) that results in tests failing for HSTS.\u00a0 We highlight this fact as it means your customer data is safe and this can be validated with tools such as Fiddler which will show the HSTS header associated with customer data access requests.\u00a0 This issue will go away when we shift all customers to use HTTPS.<\/p>\n<p>Deprecating TLS 1.0 &amp; 1.1 is expected to be a challenging task that we want to help with as much as possible by not compounding it with other major changes at the same time \u2013 Therefore, the final forced enablement of HTTPS and HSTS across all ArcGIS Online organizations is planned for spring of 2020.\u00a0 Upon this change being implemented, all customer HSTS tests will indicate successful results.<\/p>\n<p><strong>Beyond &#8211; More to come<\/strong><\/p>\n<p>TLS 1.3 \u2013 This new protocol standard was finalized in August 2018, therefore it is not widely available by cloud infrastructure providers or across browsers at this point as can be seen <a href=\"https:\/\/caniuse.com\/#search=TLS\">here<\/a>.\u00a0 We will continue to monitor TLS 1.3 for future incorporation into ArcGIS Online and have already started incorporating TLS 1.3 compatible encryption modules into some products.\u00a0 We will provide notice when it is available as part of our offerings.<\/p>\n<p>HSTS Preload List Entry &#8211; Upon forcing HTTPS only w\/HSTS across organizations, we will <strong>not<\/strong> initially add the ArcGIS Online domain to the HSTS preload list, but will consider it in the future to ensure appropriate availability and stability of our offering.<\/p>\n<p>As these changes are implemented, continue to refer to our ArcGIS SSL\/TLS Briefing, located within the <a href=\"https:\/\/trust.arcgis.com\/en\/documents\/\">ArcGIS Trust Center documents<\/a>.<\/p>\n"}],"authors":[{"ID":3911,"user_firstname":"Michael","user_lastname":"Young","nickname":"Michael Young","user_nicename":"myoung1000","display_name":"Michael Young","user_email":"myoung@esri.com","user_url":"http:\/\/trust.arcgis.com","user_registered":"2018-03-02 00:15:29","user_description":"","user_avatar":"<img data-del=\"avatar\" src='https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg' class='avatar pp-user-avatar avatar-96 photo ' height='96' width='96'\/>"}],"related_articles":"","card_image":false,"wide_image":false},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.9 (Yoast SEO v25.9) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>2019 ArcGIS Transport Security Improvements<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2019 ArcGIS Transport Security Improvements\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements\" \/>\n<meta property=\"og:site_name\" content=\"ArcGIS Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/esrigis\/\" \/>\n<meta property=\"article:modified_time\" content=\"2022-02-16T18:56:29+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@ESRI\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements\"},\"author\":{\"name\":\"Michael Young\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678\"},\"headline\":\"2019 ArcGIS Transport Security Improvements\",\"datePublished\":\"2018-11-15T19:31:45+00:00\",\"dateModified\":\"2022-02-16T18:56:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements\"},\"wordCount\":4,\"publisher\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#organization\"},\"keywords\":[\"ArcGIS Trust Center\",\"Security\"],\"articleSection\":[\"Administration\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements\",\"name\":\"2019 ArcGIS Transport Security Improvements\",\"isPartOf\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#website\"},\"datePublished\":\"2018-11-15T19:31:45+00:00\",\"dateModified\":\"2022-02-16T18:56:29+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.esri.com\/arcgis-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2019 ArcGIS Transport Security Improvements\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#website\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/\",\"name\":\"ArcGIS Blog\",\"description\":\"Get insider info from Esri product teams\",\"publisher\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.esri.com\/arcgis-blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#organization\",\"name\":\"Esri\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png\",\"contentUrl\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png\",\"width\":400,\"height\":400,\"caption\":\"Esri\"},\"image\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/esrigis\/\",\"https:\/\/x.com\/ESRI\",\"https:\/\/www.linkedin.com\/company\/5311\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678\",\"name\":\"Michael Young\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg\",\"contentUrl\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg\",\"caption\":\"Michael Young\"},\"sameAs\":[\"http:\/\/trust.arcgis.com\"],\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/author\/myoung1000\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"2019 ArcGIS Transport Security Improvements","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements","og_locale":"en_US","og_type":"article","og_title":"2019 ArcGIS Transport Security Improvements","og_url":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements","og_site_name":"ArcGIS Blog","article_publisher":"https:\/\/www.facebook.com\/esrigis\/","article_modified_time":"2022-02-16T18:56:29+00:00","twitter_card":"summary_large_image","twitter_site":"@ESRI","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements#article","isPartOf":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements"},"author":{"name":"Michael Young","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678"},"headline":"2019 ArcGIS Transport Security Improvements","datePublished":"2018-11-15T19:31:45+00:00","dateModified":"2022-02-16T18:56:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements"},"wordCount":4,"publisher":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#organization"},"keywords":["ArcGIS Trust Center","Security"],"articleSection":["Administration"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements","url":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements","name":"2019 ArcGIS Transport Security Improvements","isPartOf":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#website"},"datePublished":"2018-11-15T19:31:45+00:00","dateModified":"2022-02-16T18:56:29+00:00","breadcrumb":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/2019-arcgis-transport-security-improvements#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.esri.com\/arcgis-blog\/"},{"@type":"ListItem","position":2,"name":"2019 ArcGIS Transport Security Improvements"}]},{"@type":"WebSite","@id":"https:\/\/www.esri.com\/arcgis-blog\/#website","url":"https:\/\/www.esri.com\/arcgis-blog\/","name":"ArcGIS Blog","description":"Get insider info from Esri product teams","publisher":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.esri.com\/arcgis-blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.esri.com\/arcgis-blog\/#organization","name":"Esri","url":"https:\/\/www.esri.com\/arcgis-blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png","contentUrl":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png","width":400,"height":400,"caption":"Esri"},"image":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/esrigis\/","https:\/\/x.com\/ESRI","https:\/\/www.linkedin.com\/company\/5311\/"]},{"@type":"Person","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678","name":"Michael Young","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/image\/","url":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg","contentUrl":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg","caption":"Michael Young"},"sameAs":["http:\/\/trust.arcgis.com"],"url":"https:\/\/www.esri.com\/arcgis-blog\/author\/myoung1000"}]}},"text_date":"November 15, 2018","author_name":"Michael Young","author_page":"https:\/\/www.esri.com\/arcgis-blog\/author\/myoung1000","custom_image":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2025\/08\/Newsroom-Keyart-Wide-1920-x-1080.jpg","primary_product":"ArcGIS Trust Center","tag_data":[{"term_id":24081,"name":"ArcGIS Trust Center","slug":"ssamymlgp","term_group":0,"term_taxonomy_id":24081,"taxonomy":"post_tag","description":"","parent":0,"count":96,"filter":"raw"},{"term_id":24071,"name":"Security","slug":"security","term_group":0,"term_taxonomy_id":24071,"taxonomy":"post_tag","description":"","parent":0,"count":124,"filter":"raw"}],"category_data":[{"term_id":37501,"name":"Administration","slug":"administration","term_group":0,"term_taxonomy_id":37501,"taxonomy":"category","description":"","parent":0,"count":422,"filter":"raw"}],"product_data":[{"term_id":763582,"name":"ArcGIS Trust Center","slug":"trust-arcgis","term_group":0,"term_taxonomy_id":763582,"taxonomy":"product","description":"Reserved for articles authored by the ArcGIS Trust Center team","parent":36981,"count":86,"filter":"raw"}],"primary_product_link":"https:\/\/www.esri.com\/arcgis-blog\/?s=#&products=trust-arcgis","_links":{"self":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/blog\/359952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/users\/3911"}],"replies":[{"embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/comments?post=359952"}],"version-history":[{"count":0,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/blog\/359952\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/media?parent=359952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/categories?post=359952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/tags?post=359952"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/industry?post=359952"},{"taxonomy":"product","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/product?post=359952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}