# Tls 1.0, 1.1 off

**URL:** <https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714>\
**Category:** Server\
**Created:** [August 22, 2017, 7:01pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714 "2017-08-22T19:01:07Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krinic](https://avatars.discourse-cdn.com/v4/letter/k/e19adc/32.png) [@Krinic](https://community.letsencrypt.org/u/Krinic)\
**Post date:** [August 22, 2017, 7:01pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/1 "2017-08-22T19:01:07Z")

</div>

Hello, I hereby consult you if it is possible to disable the TLS 1.0 and 1.1 that you offer.

My bank does not allow me to integrate a payment gateway if I do not deactivate the TLS 1.0 and 1.1 protocols

I would like to know if it is possible to disable these protocols

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 22, 2017, 7:31pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/2 "2017-08-22T19:31:04Z")

</div>

Yes, but that is done on the web server settings or client browser settings.  
Which have nothing to do with the cert in use.

Where exactly are the TLS 1.0 and 1.1 found to be on that need to be disabled?

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 22, 2017, 8:16pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/3 "2017-08-22T20:16:17Z")

</div>

> [@Krinic](#):
>
> My bank does not allow me to integrate a payment gateway if I do not deactivate the TLS 1.0 and 1.1 protocols

Agreed with @rg305, and I just wanted to point out that it's kind of nice to see this happening in this particular direction rather than the other direction. (In other cases on the forum, it seemed that banks wanted security to be _reduced_ in some way in order to integrate payment gateways, while in your case they want the security to be _increased_.)

---

<div class="post-metadata">

**Author:** ![Krinic](https://avatars.discourse-cdn.com/v4/letter/k/e19adc/32.png) [@Krinic](https://community.letsencrypt.org/u/Krinic)\
**Post date:** [August 22, 2017, 8:24pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/4 "2017-08-22T20:24:13Z")

</div>

I know that this is not SSL certificate problem, the server configuration problem, the disadvantage is that shared hosting providers do not want to disable TLS 1.0 and 1.1, and I throw a lot of Lies, saying that it is problem of website code, which is not true.

Do you know what problems you may face if you disable TLS 1.0 and 1.1?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 22, 2017, 8:27pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/5 "2017-08-22T20:27:42Z")

</div>

> [@Krinic](#):
>
> Do you know what problems you may face if you disable TLS 1.0 and 1.1?

I can't think of anyone using 1.1 so that's a non-issue.  
However, and sadly, there are still plenty of 1.0 only capable clients out there.  
You would need to prefer 1.2 and look in your logs for any 1.0 connections.  
Then deal with those clients - like by upgrading them to 1.2 capable browsers.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 22, 2017, 8:29pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/6 "2017-08-22T20:29:26Z")

</div>

> [@Krinic](#):
>
> Do you know what problems you may face if you disable TLS 1.0 and 1.1?

The practical consequence is reduced browser compatibility, with loss of support for some browsers.

You can see a chart in

> **[Transport Layer Security | Web browsers](https://en.wikipedia.org/wiki/Transport_Layer_Security#Web_browsers)**
>
> As of April 2016\[update\], the latest versions of all major web browsers support TLS 1.0, 1.1, and 1.2, and have them enabled by default. However, not all supported Microsoft operating systems support the latest version of IE. Additionally, many Microsoft operating systems currently support multiple versions of IE, but this has changed according to Microsoft's Internet Explorer Support Lifecycle Policy FAQ, "beginning January 12, 2016, only the most current version of Internet Explorer available f...

that includes specific browser version compatibility. For example, to visit a site that uses only TLS 1.2, a user would need Chrome 30 or later, Firefox 27 or later, Internet Explorer 11 or later, etc.

It is a real security improvement but also a definite loss of browser compatibility. It's quite possible to imagine that the browser compatibility is a higher priority for many of the shared hosting customers, which might mean that TLS 1.2-only listener should be shifted onto a separate IP address for now. Generally for a shared IP address all sites hosted there will effectively support or not support the same set of TLS protocol versions.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 22, 2017, 9:22pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/7 "2017-08-22T21:22:16Z")

</div>

Shared hosting does not mean a forced shared cipher or protocol list.  
If your hosting provider is not able to provide individual vhost file configuration they need to upgrade their systems or you need to get another hosting provider.  
Just as easy as with specifying individual certs for individual customers, a system can specifying individualized protocols and ciphers for each customer (within their vhost file).  
Given: non-SNI capable clients will always have issues - but those issues are inherent to SNI not to differing ciphers nor protocols.

Case in point, I have multiple ciphersuites running without issue in different vhosts on the same IP.

---

<div class="post-metadata">

**Author:** ![Krinic](https://avatars.discourse-cdn.com/v4/letter/k/e19adc/32.png) [@Krinic](https://community.letsencrypt.org/u/Krinic)\
**Post date:** [August 22, 2017, 9:26pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/8 "2017-08-22T21:26:15Z")

</div>

Thank you very much for all the information you gave me, my provider already deactivated TLS protocols 1.0 and 1.1, now I just need my bank approve the payment gateway 🙂

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [August 22, 2017, 9:36pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/9 "2017-08-22T21:36:23Z")

</div>

> [@Krinic](#):
>
> the disadvantage is that shared hosting providers do not want to disable TLS 1.0 and 1.1

Please point them to:

> **[Date Change for Migrating from SSL and Early TLS](https://blog.pcisecuritystandards.org/migrating-from-ssl-and-early-tls)**
>
> The Payment Card Industry Security Standards Council (PCI SSC) is extending the migration completion date to June 30, 2018 for transitioning from SSL and TLS 1.0 to a secure version of TLS (currently v1.1 or higher).

And let them know that they'll lose _ **everyone who accepts credit cards** _ as a customer by June 2018 if they do not make this possible. This mandate does not come from your particular credit card processor but from the payment card providers themselves.

> [@Krinic](#):
>
> saying that it is problem of website code, which is not true.

I would send them links to [mod\_ssl - Apache HTTP Server Version 2.4](https://httpd.apache.org/docs/2.4/mod/mod_ssl.html#sslprotocol) and [Module ngx\_http\_ssl\_module](http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_protocols)

And make it crystal clear that I'm really starting to get the feeling that I should look for another hosting provider since it's becoming apparent that these people aren't familiar enough with SSL to be trusted with my customer's personally identifying information. 😈

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 22, 2017, 9:46pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/10 "2017-08-22T21:46:35Z")

</div>

> [@Patches](#):
>
> they’ll lose everyone who accepts credit cards as a customer by June 2018 if they do not make this possible

In this case @Krinic said that the bank wanted support for TLS 1.0 and TLS 1.1 to be disabled entirely, not just to have support for TLS 1.2 enabled. On the other hand, I think the link you provided says that PCI expects everyone in the payments industry to _be able to do_ TLS 1.1 or TLS 1.2 by next year. (Ouch, that's really quite slow. TLS 1.1 will be 12-year-old technology—and already superseded for a decade!—by the time PCI makes it mandatory.)

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [August 22, 2017, 10:17pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/11 "2017-08-22T22:17:02Z")

</div>

Well, the PCI standard is not well-known for being at the forefront of security. 😌

But they are indeed mandating that old TLS versions be disabled, not just new ones enabled: (emphasis mine)

> All entities must cutover to use _only_ a secure version of TLS (as defined by NIST) effective 30 June 2018

The deadline for _supporting_ newer TLS versions was actually in 2016.

I don't blame you for being confused. Everyone is confused. I am also confused as to whether they find TLS 1.1 to be acceptable. This seems to say it is, but my PCI automated scanning vendor (and the OPs payment gateway) seems to think it is not. Maybe the NIST recommendation changed in the interim? (I'm going to disable it anyway. 😉)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 21, 2017, 10:17pm UTC](https://community.letsencrypt.org/t/tls-1-0-1-1-off/40714/12 "2017-09-21T22:17:09Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
