An SSLv3 minimum-version setting

An SSLv3 minimum-version setting

Description

SSLv3 is obsolete and vulnerable to attacks such as POODLE. Current Go's crypto/tls does not support SSLv3: setting tls.VersionSSL30 does not enable SSLv3 connections. Remove this outdated minimum and explicitly select an organization-approved minimum from supported TLS versions.

Potential impact

  • Legacy environments that actually support SSLv3 may expose traffic to attacks such as POODLE.
  • An excessively low Go minimum can permit older supported versions such as TLS 1.0/1.1.
  • An unsupported protocol constant can mislead operators about negotiation and obscure differences between policy and deployment settings.

Remediation

  • Set tls.Config.MinVersion to at least tls.VersionTLS12, or use tls.VersionTLS13 where compatible.
  • Check the versions actually permitted by clients and servers and remove legacy dependencies.
  • Use a maintained Go release and review crypto/tls defaults and changes.
  • Check deployed negotiation with TLS tools such as nmap or sslyze.

Examples

Before

go
package main

import (
    "crypto/tls"
    "net/http"
)

func newInsecureClient() *http.Client {
    // Discouraged: set the SSLv3 constant as the minimum
    tlsConfig := &tls.Config{
        MinVersion: tls.VersionSSL30, // Current Go does not support SSLv3
    }

    return &http.Client{
        Transport: &http.Transport{
            TLSClientConfig: tlsConfig,
        },
    }
}

func main() {
    client := newInsecureClient()
    // Negotiation uses TLS versions supported by the runtime
    _, _ = client.Get("https://example.com")
}

After

go
package main

import (
    "crypto/tls"
    "net/http"
)

func newSecureClient() *http.Client {
    // Require at least TLS 1.2, or TLS 1.3 where compatible
    tlsConfig := &tls.Config{
        MinVersion: tls.VersionTLS12, // Or tls.VersionTLS13
    }

    return &http.Client{
        Transport: &http.Transport{
            TLSClientConfig: tlsConfig,
        },
    }
}

func main() {
    client := newSecureClient()
    // Use the configured TLS minimum
    _, _ = client.Get("https://example.com")
}

Explanation:

  • Before: Setting tls.VersionSSL30 does not make SSLv3 available in current Go. It is a low minimum that may permit supported legacy TLS versions.
  • After: MinVersion: tls.VersionTLS12 excludes TLS 1.0/1.1. Certificate validation and cipher suites still need appropriate configuration.

References