Description
SSLv3 is obsolete and vulnerable to attacks such as POODLE. Current Go's crypto/tls does not support SSLv3: setting tls.VersionSSL30 does not enable SSLv3 connections. Remove this outdated minimum and explicitly select an organization-approved minimum from supported TLS versions.
Potential impact
- Legacy environments that actually support SSLv3 may expose traffic to attacks such as POODLE.
- An excessively low Go minimum can permit older supported versions such as TLS 1.0/1.1.
- An unsupported protocol constant can mislead operators about negotiation and obscure differences between policy and deployment settings.
Remediation
- Set
tls.Config.MinVersionto at leasttls.VersionTLS12, or usetls.VersionTLS13where compatible. - Check the versions actually permitted by clients and servers and remove legacy dependencies.
- Use a maintained Go release and review
crypto/tlsdefaults and changes. - Check deployed negotiation with TLS tools such as
nmaporsslyze.
Examples
Before
go
package main
import (
"crypto/tls"
"net/http"
)
func newInsecureClient() *http.Client {
// Discouraged: set the SSLv3 constant as the minimum
tlsConfig := &tls.Config{
MinVersion: tls.VersionSSL30, // Current Go does not support SSLv3
}
return &http.Client{
Transport: &http.Transport{
TLSClientConfig: tlsConfig,
},
}
}
func main() {
client := newInsecureClient()
// Negotiation uses TLS versions supported by the runtime
_, _ = client.Get("https://example.com")
}
After
go
package main
import (
"crypto/tls"
"net/http"
)
func newSecureClient() *http.Client {
// Require at least TLS 1.2, or TLS 1.3 where compatible
tlsConfig := &tls.Config{
MinVersion: tls.VersionTLS12, // Or tls.VersionTLS13
}
return &http.Client{
Transport: &http.Transport{
TLSClientConfig: tlsConfig,
},
}
}
func main() {
client := newSecureClient()
// Use the configured TLS minimum
_, _ = client.Get("https://example.com")
}
Explanation:
- Before: Setting
tls.VersionSSL30does not make SSLv3 available in current Go. It is a low minimum that may permit supported legacy TLS versions. - After:
MinVersion: tls.VersionTLS12excludes TLS 1.0/1.1. Certificate validation and cipher suites still need appropriate configuration.