IRCTC e-ticketing website migration to TLS 1.2

Futureized

Skilled
Hope anyone received same..

Edit: on there email about irctc changes.
Not major changes.. but something..
Windows xp and 2003 upgraded..

!!!!!!!!!!
 
That is because IRCTC is using SAP(or some other ERP tool) and TLS 1.2 has become the new mandate/base for all encrypted communication.
And sadly older windows do not support TLS 1.2.
On linux, an upgraded cryptolib is a workaround.
Had a tough time implementing TLS 1.2 for our customer with lot of hit-and-miss trials in defining the encryption algorithm-support bracket for communication with external vendors.

The image in the email is taken from here.
For non-technical people, its simply an upgraded security protocol for communicating with IRCTC servers.
 
Last edited:
Does this even matter now? Almost all payment gateways and banking sites require to be on TLS 1.2 for PCI DSS compliance since Jul 2018.

When we say that Win XP doesn't support TLS1.2, it means that Microsoft's own TLS engine SCHANNEL doesn't support it. Applications using a fairly newer version of Open SSL or its variants and NSS will support it.

Which mainly boils down to IE on Win XP doesn't support TLS1.2. It would be pretty ballsy of someone to be sitting tight on Win XP and using IE to browse the web in 2019.
 
Last edited:
Which mainly boils down to IE on Win XP doesn't support TLS1.2. It would be pretty ballsy of someone to be sitting tight on Win XP and using IE to browse the web in 2019.
There can be remote places where XP and BSNL's 64 kbps/dial-in internet will be the only available choice.
Our customer still uses Windows Server 2003 which is not supported and we literally had to change the setup to use SFTP instead of HTTP since the customer did not want to touch their legacy application.
It had to be a new development altogether with lot of hours. But then we had no choice.
 
It would be pretty ballsy of someone to be sitting tight on Win XP and using IE to browse the web in 2019.
I already tried that and even google crashes forget other sites which give errors as if we are accessing infectious website. Https isnt recognized in xp and the tls issue makes everything even difficult.
Also, many mncs are still stuck with server 2k3 and 2k8, seems they fear migrations or something.
Developers already got bored to program production applications to run on age old platforms but they got no choice either.
They are leaving such cos. as programming for stale platforms affects their learning and resume further.
 
Back
Top