Skip to content

TLS and HTTPS

Which TLS versions should you support?

Which protocol versions the server accepts: whether obsolete SSL 3.0, TLS 1.0 and TLS 1.1 are still enabled, and whether TLS 1.3 is offered.

Part of the External Security Check. Free during the preview.

What it checks

Which protocol versions the server accepts: whether obsolete SSL 3.0, TLS 1.0 and TLS 1.1 are still enabled, and whether TLS 1.3 is offered.

TLS protocol versions. A pass means: Obsolete SSL and TLS versions are disabled.

TLS 1.3 support. A pass means: TLS 1.3 is supported.

Possible findings

SSL 3.0 is enabled

Severity: HighConfidence: ConfirmedKind: Security issue

What we found

The server accepted an SSL 3.0 connection.

Why it matters

SSL 3.0 is broken (POODLE) and was prohibited in 2015. No current browser needs it.

How to fix it

Disable SSL 3.0. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache use SSLProtocol -all +TLSv1.2 +TLSv1.3.

TLS 1.0 is enabled

Severity: MediumConfidence: ConfirmedKind: Security issue

What we found

The server accepted a TLS 1.0 connection.

Why it matters

TLS 1.0 is obsolete and was formally deprecated in 2021. It lacks modern protections, and PCI DSS and most security baselines require it to be disabled.

How to fix it

Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.

TLS 1.1 is enabled

Severity: MediumConfidence: ConfirmedKind: Security issue

What we found

The server accepted a TLS 1.1 connection.

Why it matters

TLS 1.1 is obsolete and was formally deprecated in 2021 alongside TLS 1.0.

How to fix it

Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3.

TLS 1.3 is not supported

Severity: InformationConfidence: ConfirmedKind: Recommended hardening

What we found

The server did not negotiate TLS 1.3.

Why it matters

TLS 1.3 is faster and removes legacy options that have caused vulnerabilities. TLS 1.2 remains acceptable, so this is a recommendation rather than a problem.

How to fix it

Enable TLS 1.3 alongside TLS 1.2. Recent versions of nginx, Apache, IIS (Windows Server 2022) and all major CDNs support it.

References