Weak TLS protocols

Weak TLS protocols

Description

SSLv2, SSLv3, TLS 1.0, and TLS 1.1 are no longer considered secure protocols.

Potential impact

  • The risk of downgrade attacks, ciphertext decryption, or man-in-the-middle attacks increases.

Remediation

Require TLS 1.2 or later and remove obsolete protocol methods and settings.

Examples

These excerpts compare configuration. In production code, check that context creation and minimum-version configuration succeed before using the context.

Before

c
SSL_CTX *ctx = SSL_CTX_new(TLSv1_method());

After

c
SSL_CTX *ctx = SSL_CTX_new(TLS_method());
SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION);

Explanation:

  • Before: The method allows only TLS 1.0.
  • After: A version-flexible TLS method is used with an explicit minimum version.

References