Quicksight EmbedURL using TLS 1.0

0

Hi, I've built an application for the Salesforce.com AppExchange. This application Embeds a Quicksight Dashboard using this API call [GetSessionEmbedUrl] (https://docs.aws.amazon.com/quicksight/latest/APIReference/API_GetSessionEmbedUrl.html). Salesforce.com will not approve my application because their security scan is picking up the fact that this API fetches the Embedded URL using "https://api.us-east-2.quicksight.aws.amazon.com" which still has access to TLS V1.0 (they require all APIs to disable TLS v1.0). I've asked them to consider this as a 'false positive' given I can't change how the API works, but wondering if anyone has run into a case like this before and has any advice?

dmarcus
已提問 2 年前檢視次數 290 次
1 個回答
0

Thanks for sharing the challenge. QuickSight endpoint currently supports TLS1.0 for few legacy clients but is planning to deprecate that support.

Please feel free to get in touch with Customer Support to explore options or to get an update.

AWS
Vijay
已回答 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南