# How to disable TLSv1

**URL:** https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117
**Category:** Help
**Created:** [December 28, 2017, 8:46am UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117 "2017-12-28T08:46:15Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![benjaone](https://avatars.discourse-cdn.com/v4/letter/b/d9b06d/32.png) [@benjaone](https://community.letsencrypt.org/u/benjaone)
#### Post date: [December 28, 2017, 8:46am UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/1 "2017-12-28T08:46:15Z")

</div>

Hi,

I finally managed to get my certificate, nice!

[https://www.benjaminthompson.org](https://www.benjaminthompson.org)

I would like to disable TLSv1 though.

When I look after /etc/httpd/conf.d/ssl.conf file doesn’t exist?

So how and where do I make the changes?

Thanks

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [December 28, 2017, 9:06am UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/2 "2017-12-28T09:06:00Z")

</div>

first try locating the vhost config file:  
`grep -ri benjaminthompson.org /etc/httpd`

---

<div class="post-metadata">

### Author: ![benjaone](https://avatars.discourse-cdn.com/v4/letter/b/d9b06d/32.png) [@benjaone](https://community.letsencrypt.org/u/benjaone)
#### Post date: [December 28, 2017, 11:21am UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/3 "2017-12-28T11:21:37Z")

</div>

Hi rg305,

I get:

grep: /etc/httpd: No such file or directory

Thanks

---

<div class="post-metadata">

### Author: ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)
#### Post date: [December 28, 2017, 11:50am UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/4 "2017-12-28T11:50:04Z")

</div>

is it below /etc/apache2/ ? if not, could you tell us a little more about your config ( what is your OS etc )

From your other posts - probably  
/etc/apache2/sites-available/benjaminthompson.org.conf  
/etc/apache2/sites-available/benjaminthompson.org-lessl.conf

---

<div class="post-metadata">

### Author: ![benjaone](https://avatars.discourse-cdn.com/v4/letter/b/d9b06d/32.png) [@benjaone](https://community.letsencrypt.org/u/benjaone)
#### Post date: [December 28, 2017, 12:07pm UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/5 "2017-12-28T12:07:22Z")

</div>

Hi serverco,

/etc/apache2/sites-available/benjaminthompson.org.conf

\<VirtualHost \*:80\>  
ServerName [benjaminthompson.org](http://benjaminthompson.org)  
DocumentRoot /var/www/html  
RewriteEngine on  
RewriteCond %{SERVER\_NAME} =[benjaminthompson.org](http://benjaminthompson.org)  
RewriteRule ^ https://%{SERVER\_NAME}%{REQUEST\_URI} [END,NE,R=permanent]  
  
\<VirtualHost \*:80\>  
ServerName [www.benjaminthompson.org](http://www.benjaminthompson.org)

RewriteEngine on  
RewriteCond %{SERVER\_NAME} =[www.benjaminthompson.org](http://www.benjaminthompson.org)  
RewriteRule ^ https://%{SERVER\_NAME}%{REQUEST\_URI} [END,NE,R=permanent]

/etc/apache2/sites-available/benjaminthompson.org-le-ssl.conf

 ServerName benjaminthompson.org DocumentRoot /var/www/html SSLCertificateFile /etc/letsencrypt/live/www.benjaminthompson.org/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/www.benjaminthompson.org/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf ServerName www.benjaminthompson.org

SSLCertificateFile /etc/letsencrypt/live/www.benjaminthompson.org/fullchain.pem  
SSLCertificateKeyFile /etc/letsencrypt/live/www.benjaminthompson.org/privkey.pem  
Include /etc/letsencrypt/options-ssl-apache.conf

I’m having issues getting caching plugins to work since I got my SSL certificate, don’t know if my issues are related.

Thanks

---

<div class="post-metadata">

### Author: ![benjaone](https://avatars.discourse-cdn.com/v4/letter/b/d9b06d/32.png) [@benjaone](https://community.letsencrypt.org/u/benjaone)
#### Post date: [December 28, 2017, 12:07pm UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/6 "2017-12-28T12:07:45Z")

</div>

I’m using puTTY from WIN10

---

<div class="post-metadata">

### Author: ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)
#### Post date: [December 28, 2017, 12:38pm UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/7 "2017-12-28T12:38:45Z")

</div>

I’d suggest using [https://mozilla.github.io/server-side-tls/ssl-config-generator/](https://mozilla.github.io/server-side-tls/ssl-config-generator/) to provide the optimal config for your site.

Adding

```
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1

```

in your config after the

```
SSLCertificateFile /etc/letsencrypt/live/www.benjaminthompson.org/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/www.benjaminthompson.org/privkey.pem

```

lines will disable SSLv3, TLSv1 and TLSv1.1 although that will also prevent connection from some of the less modern browsers.

You should also check if these are set at all in

```
/etc/letsencrypt/options-ssl-apache.conf
```

---

<div class="post-metadata">

### Author: ![benjaone](https://avatars.discourse-cdn.com/v4/letter/b/d9b06d/32.png) [@benjaone](https://community.letsencrypt.org/u/benjaone)
#### Post date: [December 28, 2017, 12:52pm UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/8 "2017-12-28T12:52:15Z")

</div>

Thanks!

How is my /etc/letsencrypt/options-ssl-apache.conf supposed to look after I have disabled TLsv?

This is how it is now:

```
# This file contains important security parameters. If you modify this file
# manually, Certbot will be unable to automatically provide future security
# updates. Instead, Certbot will print and log an error message with a path to
# the up-to-date file that you will need to refer to when manually updating
# this file.

```

SSLEngine on

```
# Intermediate configuration, tweak to your needs
SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-
SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-
AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-
SHA256:ECDHE-EC$
SSLHonorCipherOrder on
SSLCompression off

```

SSLOptions +StrictRequire

```
# Add vhost name to log entries:
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-agent}i\"" vhost_combined
LogFormat "%v %h %l %u %t \"%r\" %>s %b" vhost_common

#CustomLog /var/log/apache2/access.log vhost_combined
#LogLevel warn
#ErrorLog /var/log/apache2/error.log

# Always ensure Cookies have "Secure" set (JAH 2012/1)
#Header edit Set-Cookie (?i)^(.*)(;\s*secure)??((\s*;)?(.*)) "$1; Secure$3$4"

```

I will install [https://mozilla.github.io/server-side-tls/ssl-config-generator/](https://mozilla.github.io/server-side-tls/ssl-config-generator/)

and add:

```
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1

```

Right now.

Thanks! 🙂

---

<div class="post-metadata">

### Author: ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)
#### Post date: [December 28, 2017, 12:56pm UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/9 "2017-12-28T12:56:11Z")

</div>

You don’t need to “install” the mozilla SSL config generator - it’s a web page that gives you example configs.

As long as the /etc/letsencrypt/options-ssl-apache.conf doesn’t include any SSLProtocol line, which would overwrite the previous one - then that’s fine.

---

<div class="post-metadata">

### Author: ![benjaone](https://avatars.discourse-cdn.com/v4/letter/b/d9b06d/32.png) [@benjaone](https://community.letsencrypt.org/u/benjaone)
#### Post date: [December 28, 2017, 1:01pm UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/10 "2017-12-28T13:01:53Z")

</div>

PERFECT!!!

```
https://www.whynopadlock.com/results/e38afde3-320d-4f51-9388-63fbac1086c4

```

Thank you very much sir !

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [January 27, 2018, 1:02pm UTC](https://community.letsencrypt.org/t/how-to-disable-tlsv1/49117/11 "2018-01-27T13:02:06Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
