Providing custom mortgage credit reports, related services & technology solutions for over 75 years.



Security Update: Avantus Removing Support of TLS 1.0 and 1.1

August 28, 2017

In accordance with industry best practices, Avantus will remove support for TLS 1.0 and 1.1 on December 15, 2017. Your action is required prior to this date to ensure continued access to Avantus services.

What is TLS?

TLS ("Transport Layer Security") is the protocol that protects data while in transit between Avantus and its partners and clients. It is the most widely deployed security protocol used today, and is used for web browsers and other applications that require data to be securely exchanged over the Internet. There are three versions of TLS currently in use: TLS 1.0, 1.1 and 1.2.

What is changing?

Beginning December 15, 2017, Avantus will no longer accept connections from clients using TLS version 1.0 and 1.1. Only clients using TLS 1.2 will be able to successfully connect to Avantus systems.

Why is this change occurring?

Avantus continuously monitors the information technology threat environment and published security best practices. Several industry groups, such as the PCI Council and the U.S. Government's National Institute of Standards and Technology have determined that TLS versions 1.0 and 1.1 no longer provide adequate protection for sensitive consumer information and should be removed from service. Based on these recommendations, Avantus has decided to remove support for TLS versions 1.0 and 1.1 as of December 15, 2017.

How can customers avoid disruptions in their service?

Avantus recommends that clients discuss this notice with their internal IT staff to determine what impact (if any) this change will have on your users. While most recently-updated desktop web browsers support TLS version 1.2 by default, customers should pay particular attention non-browser systems that may communicate with Avantus, such as LOS platforms and any custom-developed software systems. Most software vendors such as Microsoft, Apple, Google, and Oracle publish tables detailing when their products first supported TLS 1.2. This information can assist your internal IT staff in determining whether any upgrades are needed to avoid a disruption to your access to Avantus systems.

How can I test my systems prior to the December 15, 2017 deadline?

There are a number of third-party tools available to determine whether your web browser supports TLS 1.2. For example, the tool will test and display the TLS capabilities of your web browser.

Clients wanting to perform more in-depth testing with Avantus are encouraged to contact their account representative to review their testing needs.




If you liked this article, consider signing up for our weekly Buzz recap email! Sent every Friday morning, it's a quick way to catch up on all the industry news and happenings at Avantus. Click here to sign up!