# How can i enable TLS1.0&1.1?

**URL:** <https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444>\
**Category:** Help\
**Created:** [December 18, 2018, 4:06pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444 "2018-12-18T16:06:17Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![pccloob](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@pccloob](https://community.letsencrypt.org/u/pccloob)\
**Post date:** [December 18, 2018, 4:06pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/1 "2018-12-18T16:06:17Z")

</div>

hi everyone  
i use Let’s Encrypt SSL in my site: [https://pccloob.ir](https://pccloob.ir)  
i enable it from my host.but the TLS 1.0 & 1.1 is not enabled and my app dont work in android \< 4.4  
i want enable TLS 1.0 & 1.1 so my app work in android \< 4.4 too.  
please help me.  
thanks

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 18, 2018, 4:20pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/2 "2018-12-18T16:20:51Z")

</div>

Protocol setting are controlled by the web service (not the certificate used).  
Your web server/service should probably have a configuration file that can be modified to include/exclude protocols and ciphers, etc.

[edit]  
Or in the case of LightSpeed, perhaps a management/admin area something like:  
[http://internal.ip:7080/](http://internal.ip:7080/)

---

<div class="post-metadata">

**Author:** ![pccloob](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@pccloob](https://community.letsencrypt.org/u/pccloob)\
**Post date:** [December 18, 2018, 4:26pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/3 "2018-12-18T16:26:41Z")

</div>

so,i should contact with my host manager?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 18, 2018, 4:28pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/4 "2018-12-18T16:28:28Z")

</div>

If you have “root” access, you can “manage” it yourself.  
It you have access to a cPanel (or such) for it, you might be able to make the necessary changes.  
If you are unsure about anything, yes, I would first talk with the hosting company about where/how to best make such changes.

---

<div class="post-metadata">

**Author:** ![pccloob](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@pccloob](https://community.letsencrypt.org/u/pccloob)\
**Post date:** [December 18, 2018, 4:39pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/5 "2018-12-18T16:39:50Z")

</div>

i have cpanel access.  
SSL/TLS  
SSL/TLS Status  
Lets Encrypt™ SSL  
how can enable TLS 1.0 & 1.1?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 18, 2018, 4:44pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/6 "2018-12-18T16:44:31Z")

</div>

You should ask your hosting provider first.

---

<div class="post-metadata">

**Author:** ![pccloob](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@pccloob](https://community.letsencrypt.org/u/pccloob)\
**Post date:** [December 18, 2018, 5:21pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/8 "2018-12-18T17:21:48Z")

</div>

please tell me what i do?  
i contact my hosting provider and tell them.  
what i tell them exactly?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 18, 2018, 5:44pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/9 "2018-12-18T17:44:55Z")

</div>

> [@pccloob](#):
>
> what i tell them exactly?

Tell them exactly the same that you told us here.  
_"How can I enable TLS1.0&1.1?"_  
_"I want enable TLS 1.0 & 1.1 so my app works in android \< 4.4"_

---

<div class="post-metadata">

**Author:** ![pccloob](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@pccloob](https://community.letsencrypt.org/u/pccloob)\
**Post date:** [December 19, 2018, 9:22am UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/10 "2018-12-19T09:22:28Z")

</div>

i ask him but they said : we can not enable it. because you are in the Shared Host. if you want do this must buy dedicated server.  
😭

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 19, 2018, 2:24pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/11 "2018-12-19T14:24:59Z")

</div>

If you have access to any other Internet connected server that has TLS1.0 or TLS1.1 enabled, maybe you can use that one to proxy to this one.

Otherwise, you may need to change to dedicated server or change hosting company.

---

<div class="post-metadata">

**Author:** ![pccloob](https://avatars.discourse-cdn.com/v4/letter/p/73ab20/32.png) [@pccloob](https://community.letsencrypt.org/u/pccloob)\
**Post date:** [December 19, 2018, 3:39pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/12 "2018-12-19T15:39:59Z")

</div>

no i dont have.  
hosting manager said : i have to buy premium ssl. in premium ssl there is no problem with tls 1.0 and 1.1  
but in free ssl there is problem.  
is that true?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [December 19, 2018, 3:50pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/13 "2018-12-19T15:50:13Z")

</div>

There’s no technical requirement.

Your host is choosing to do this for business reasons, or because it’s convenient with their software.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [December 19, 2018, 6:13pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/14 "2018-12-19T18:13:11Z")

</div>

The other possible reason is that some sites that accept credit cards were told to disable it due to an industry requirement (because it’s considered obsolete). So, if this host has other customers who are subject to that rule, it might have disabled these protocol versions because that’s what the other customers want due to these industry rules.

In this case, it might be hard for the host to make everyone happy on the same shared server, because disabling the old TLS versions will reduce compatibility with old devices. But _not_ disabling them will show a warning on scanners that check for payment industry rules. It’s pretty hard to support a different set of TLS versions on the same shared server for different customers.

I agree with @mnordhoff’s point that this is mostly a business decision, but in this case the host might have reasons other than only wanting you to pay more—complying with your request might have negative consequences for some other customers.

Probably the easiest choices would be to find a host that’s similar to your current host but that happens to have these old TLS versions enabled (maybe because it doesn’t have any customers who accept credit cards directly on their sites), or to buy a VPS plan from any provider that offers one. (In this case, you are the system administrator and you directly control the TLS configuration and other system settings. This gives you much more responsibility around things like installing, configuring, and updating system software, and also more control over all of the system configuration options.)

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [December 19, 2018, 6:21pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/15 "2018-12-19T18:21:38Z")

</div>

> [@schoen](#):
>
> It’s pretty hard to support a different set of TLS versions on the same shared server for different customers.

It is technically possible, but it's a lot of extra work because no popular software for hosting web sites provides an easy way to do this automatically. So a shared hosting provider basically has three options:

- Enable TLS 1.0 and 1.1 for everyone (makes @pccloob happy because of device compatibility, but makes other customers unhappy)
- Disable TLS 1.0 and 1.1 for everyone (makes other customers unhappy because of payment industry rules, but makes @pccloob unhappy)
- Do a lot of extra work to create a very custom configuration

But this isn't an issue on a VPS or dedicated plan, because the customer can choose the configuration for the whole server. In this case, you could look at

[https://mozilla.github.io/server-side-tls/ssl-config-generator/](https://mozilla.github.io/server-side-tls/ssl-config-generator/)

for server configuration recommendations that achieve the desired compatibility with older clients.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 20, 2018, 1:22am UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/16 "2018-12-20T01:22:42Z")

</div>

> [@schoen](#):
>
> Do a lot of extra work to create a very custom configuration

I believe this is a lot simpler than most people think:  
I've been able to serve different protocols for different vhost configs.  
The main catch is that the base/default system must combine all protocols required by all tenants.  
Then each tenant is free to chose (within their vhost) which protocol they want to use.

Once the base has been set (say to TLSv1.2 ONLY), their is no way for any tenant vhost config to expand on that base (their settings get ignored).

---

<div class="post-metadata">

**Author:** ![tdelmas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/tdelmas/32/1866_2.png) [@tdelmas](https://community.letsencrypt.org/u/tdelmas)\
**Post date:** [December 28, 2018, 5:26pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/17 "2018-12-28T17:26:34Z")

</div>

(I moved that subject to #help instead of #help:aide-en-francais)

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [December 28, 2018, 7:46pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/18 "2018-12-28T19:46:53Z")

</div>

> [@rg305](#):
>
> Otherwise, you may need to change to dedicated server or change hosting company.

I think there's no shared hosting provider would adjust their cPanel / WHM protocal settings just for single user's request..... (Not to mention for the newer version of cPanel / WHM, it's relatively hard for host technicans to adjust protocol.... since cpanel disabled it from coding side)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [January 27, 2019, 7:46pm UTC](https://community.letsencrypt.org/t/how-can-i-enable-tls1-0-1-1/80444/19 "2019-01-27T19:46:58Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
