Release
Time to upgrade your company’s online banking security
OP’s Web Services will stop supporting old versions of the TLS cryptographic protocol in March 2021. Make sure that your online banking software runs on a supported version, as you will not be able to transmit your company’s data to banks using the old TLS versions 1.0 and 1.1 after 24 March 2021. If you have not upgraded your software, you will not be able to make payments via Web Services.
Limiting support to the latest versions is designed to increase the level of data security. The Finnish Transport and Communications Agency’s regulation on electronic identification and trust services recommends primarily using TLS version 1.2 or later to encrypt and decrypt data transmissions.
We have given our customers several heads-up about the phasing out of old versions and urged them to upgrade their online banking systems. The majority of software suites used by businesses are already up to date, but a few still run on old versions. Old versions will not be supported after 24 March 2021, which is the absolute final deadline for upgrading. Make sure that your software is up to date.
What is Transport Layer Security (TLS)?
TLS is a data security protocol that ensures the protection and integrity of data between two communicating applications. It is widely used in web browsers and other applications requiring secure transfer of data over a computer network.
Get to know TLS version 1.2 in our test environment
You can use our Web Services test environment to send and receive data between your company’s software and your bank and see for yourself how the TLS cryptographic protocol protects your data transmissions in practice. We have also prepared instructions for using the test environment (PDF) (in Finnish).
Supported cipher suites
OP is in the process of upgrading the security of Web Services and discontinuing the use of TLS 1.0 and 1.1 protocols. Several old cipher suites will no longer be supported.
OP supports the following cipher suites:
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
What is a cipher suite?
TLS uses so-called cipher suites to encrypt and decrypt transmitted data. A cipher suite is a set of algorithms that help to secure network connections that rely on TLS.