# Disabling TLS 1.0 and TLS 1.1

**URL:** <https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816>\
**Category:** Help\
**Created:** [February 10, 2020, 4:53pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816 "2020-02-10T16:53:18Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![dw21677](https://avatars.discourse-cdn.com/v4/letter/d/dbc845/32.png) [@dw21677](https://community.letsencrypt.org/u/dw21677)\
**Post date:** [February 10, 2020, 4:53pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/1 "2020-02-10T16:53:18Z")

</div>

I maintain several websites that use Certbot. The Qualys SSL Labs SSL Server Test has historically graded them as A+, but recently the grade has changed to B:

"This server supports TLS 1.0 and TLS 1.1. Grade capped to B. "

I could disable those protocols. For Apache, it would seem to require changing the SSLProtocol line in /etc/letsencrypt/options-ssl-apache.conf. But that file warns: “If you modify this file manually, Certbot will be unable to automatically provide future security updates.”

So, how can you disable TLS 1.0 and TLS 1.1, but still get configuration updates from Certbot? Will Certbot disable these obsolete protocols in the near future? Any advice would be appreciated.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 10, 2020, 4:59pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/2 "2020-02-10T16:59:42Z")

</div>

> [@dw21677](#):
>
> So, how can you disable TLS 1.0 and TLS 1.1, but still get configuration updates from Certbot?

In Apache, search through your configuration files for " **SSLProtocol**".  
Set it to:  
**SSLProtocol +TLSv1.2**  
[and restart Apache]

This change will not break certbot updates.

---

<div class="post-metadata">

**Author:** ![dw21677](https://avatars.discourse-cdn.com/v4/letter/d/dbc845/32.png) [@dw21677](https://community.letsencrypt.org/u/dw21677)\
**Post date:** [February 10, 2020, 5:26pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/3 "2020-02-10T17:26:06Z")

</div>

> [@rg305](#):
>
> In Apache, search through your configuration files for “ **SSLProtocol** ”.  
> Set it to:  
> **SSLProtocol +TLSv1.2**  
> [and restart Apache]
> 
> This change will not break certbot updates.

Thanks, I tried this, except for Nginx instead of Apache. (Sorry to confuse the issue, but it's probably the same problem for both Nginx and Apache.) I first changed /etc/nginx/nginx.conf, but found that I could not disable TLS 1.0 and TLS 1.1 unless I also edited /etc/letsencrypt/options-ssl-nginx.conf. That would presumably break Certbot updates because, as options-ssl-nginx.conf says: "If you modify this file manually, Certbot will be unable to automatically provide future security updates.”

It seems either that comment in the .conf file is wrong or Certbot updates will be broken.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 10, 2020, 5:34pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/4 "2020-02-10T17:34:38Z")

</div>

Relying on certbot for (any) future security updates is not an ideal _best practice_.  
SSL Labs can better show you when/where your systems are _out of compliance_; from there you can and should take steps to ensure your systems are up to your minimum security standards.

And for those that do absolutely _nothing_ to secure and maintain their systems, certbot may eventually steer them to a safer security configuration.

[sadly unlike say _driving a car_, there is no test, nor license required, to operate a web server]

---

<div class="post-metadata">

**Author:** ![dw21677](https://avatars.discourse-cdn.com/v4/letter/d/dbc845/32.png) [@dw21677](https://community.letsencrypt.org/u/dw21677)\
**Post date:** [February 10, 2020, 5:46pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/5 "2020-02-10T17:46:26Z")

</div>

> [@rg305](#):
>
> Relying on certbot for (any) future security updates is not an ideal _best practice_ .  
> SSL Labs can better show you when/where your systems are _out of compliance_ ; from there you can and should take steps to ensure your systems are up to your minimum security standards.
> 
> And for those that do absolutely _nothing_ to secure and maintain their systems, certbot may eventually steer them to a safer security configuration.

Makes sense. Some of the Certbot-using websites I maintain, I don't administrate the systems so I have to request changes to web server configuration. Unfortunately, the administrators can be derelict about security maintenance, so I worry breaking the Certbot automatic updates for a one-off security improvement will just make security worse in the long run. I think I'll just hope that Certbot removes TLS 1.0 and TLS 1.1 from the default configurations eventually. It'd be nice if there were some way to make the change to remove TLS 1.0 and TLS 1.1 without breaking future Certbot configuration updates.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 10, 2020, 5:58pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/6 "2020-02-10T17:58:29Z")

</div>

> [@dw21677](#):
>
> It’d be nice if there were some way to make the change to remove TLS 1.0 and TLS 1.1 without breaking future Certbot configuration updates.

For that plan, I would keep certbot updated [and also monitor the site with SSL Labs every couple of months].

---

<div class="post-metadata">

**Author:** ![ZetaRevan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zetarevan/32/37496_2.png) [@ZetaRevan](https://community.letsencrypt.org/u/ZetaRevan)\
**Post date:** [February 10, 2020, 6:04pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/7 "2020-02-10T18:04:16Z")

</div>

TBH, I don’t even use the Certbot Apache config. I configure my VirtualHosts manually and hold a global SSL Configuration:

RHEL/CentOS: /etc/httpd/conf.d/ssl.conf  
Debian/Ubuntu: /etc/apache2/mods-enabled/ssl.conf  
SSLProtocol ALL -SSLv2 -SSLv3 -TLSv1 -TLSv1.1  
SSLCipherSuite ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:!aNULL:!MD5:!DSS:!SHA1;

Not sure what file it might reside on with nginx, but the syntax is:  
ssl\_protocols TLSv1.2;  
ssl\_ciphers ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:!aNULL:!MD5:!DSS:!SHA1

EDIT:  
The SSLProtocol line in Apache can be shortened to:  
`SSLProtocol -ALL +TLSv1.2 +TLSv1.3`  
If you want to be explicit. I keep my template the other way so I don’t have to worry about that particular configuration in the future when things progress to later TLS versions.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 10, 2020, 6:09pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/8 "2020-02-10T18:09:52Z")

</div>

Here is the “default” found in nginx.conf (Ubuntu 18.04 - nginx 1.14.0):

```auto
        ##
        # SSL Settings
        ##

        ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE
        ssl_prefer_server_ciphers on;

```

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [February 11, 2020, 1:42am UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/9 "2020-02-11T01:42:35Z")

</div>

The most recent version of Certbot did disable TLS 1.0 and 1.1 in the Apache configuration.

If you can’t upgrade Certbot, I guess you could steal its configuration file. Then there shouldn’t be problems with future upgrades.

> <https://github.com/certbot/certbot/blob/v1.2.0/certbot-apache/certbot_apache/_internal/options-ssl-apache.conf>

---

<div class="post-metadata">

**Author:** ![crimson\_king](https://avatars.discourse-cdn.com/v4/letter/c/9de0a6/32.png) [@crimson\_king](https://community.letsencrypt.org/u/crimson_king)\
**Post date:** [March 5, 2020, 1:54am UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/10 "2020-03-05T01:54:12Z")

</div>

Ubuntu Server 18.04 LTS, Apache 2.4, Certbot 0.31.0

**Things I’ve tried:**

- I tried to change `SSLProtocol` in the file `/etc/apache2/mods-available/ssl.conf` and restart the server, but it didn’t work.
- I searched for `SSLProtocol` in the main Apache configuration file `/etc/apache2/apache2.conf`, but it isn’t there.
- I tried to set `SSLProtocol` on all enabled virtual host files in `/etc/apache2/sites-available/*`, but the SSL Labs test still reported that my server had support for TLSv1.0 and TLSv1.1.

It only worked when I changed it in `/etc/letsencrypt/options-ssl-apache.conf`.

I’m okay with that, actually. I always apply updates myself anyway. But does anyone know how else could I successfully change SSLProtocol in a similar setup?

---

<div class="post-metadata">

**Author:** ![ZetaRevan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zetarevan/32/37496_2.png) [@ZetaRevan](https://community.letsencrypt.org/u/ZetaRevan)\
**Post date:** [March 5, 2020, 6:42am UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/11 "2020-03-05T06:42:26Z")

</div>

Apache files are read top to bottom. The ssl.conf file should take the global setting, but it has to be OUTSIDE the default VirtualHost block. In your vhost config files, remove the line:

`Include /etc/letsencrypt/options-ssl-apache.conf`

I have my own SSL settings globally set in my ssl.conf file.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 5, 2020, 9:55am UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/12 "2020-03-05T09:55:13Z")

</div>

Also enable TLS 1.3, if your Apache version supports it.

If you need inspiration, look here: [ssl-config.mozilla.org/](http://ssl-config.mozilla.org/)

And here: [https://httpd.apache.org/docs/current/mod/mod\_ssl.html](https://httpd.apache.org/docs/current/mod/mod_ssl.html)

---

<div class="post-metadata">

**Author:** ![ZetaRevan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zetarevan/32/37496_2.png) [@ZetaRevan](https://community.letsencrypt.org/u/ZetaRevan)\
**Post date:** [March 5, 2020, 12:44pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/13 "2020-03-05T12:44:59Z")

</div>

> [@9peppe](#):
>
> Also enable TLS 1.3, if your Apache version supports it.

It's not only based on apache/nginx version. It's also based on OpenSSL version. Needs to be 1.1.1+. It's not available on standard repos for RHEL/CentOS7 or Ubuntu 18.04. Not sure where it starts being available on other distros standard repos. I have CentOS8, and it's available on the standard repos.

I'm sure you can download it & do a manual install, but it's not easy for the average user.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 5, 2020, 12:57pm UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/14 "2020-03-05T12:57:21Z")

</div>

> [@ZetaRevan](#):
>
> It’s also based on OpenSSL version. Needs to be 1.1.1+. It’s not available on standard repos for RHEL/CentOS7 or Ubuntu 18.04

1.1.1 should be routinely available on up-to-date Ubuntu 18.04 systems now.

When 1.1.0 went EOL, Ubuntu backported 1.1.1.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 6, 2020, 5:02am UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/15 "2020-03-06T05:02:27Z")

</div>

Also on the positive side of the things to consider list:

- enabling TLSv1.3 on web servers won’t break anything when OpenSSL doesn’t support it yet.  
[that’s just “pre-configuration” for the day it does - you could even “allow” TLSv1.4 or TLSv2.0]

---

<div class="post-metadata">

**Author:** ![ZetaRevan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zetarevan/32/37496_2.png) [@ZetaRevan](https://community.letsencrypt.org/u/ZetaRevan)\
**Post date:** [March 6, 2020, 5:06am UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/16 "2020-03-06T05:06:49Z")

</div>

Sure. It’s why I choose to use

`SSLProtocol ALL -SSLv2 -SSLv3 -TLSv1 -TLSv1.1`

Leaves it open for TLSv1.2+

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 5, 2020, 5:06am UTC](https://community.letsencrypt.org/t/disabling-tls-1-0-and-tls-1-1/112816/17 "2020-04-05T05:06:50Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
