Review the minimum TLS version

Review the minimum TLS version

Description

Allowing older protocols such as TLS 1.0/1.1 can weaken transport protection. However, current Go crypto/tls defaults to TLS 1.2 when MinVersion is omitted, so omission alone does not establish an insecure connection. Check the deployed Go version and environment settings, and specify the minimum TLS version required by the service.

Potential impact

  • Negotiating an old protocol or weak cipher suite can reduce the confidentiality and integrity of sensitive information.
  • Unchecked runtime defaults or exception settings may differ from the organization's required minimum.
  • An unnecessarily high minimum can also disconnect required clients, so check compatibility during migration.

Remediation

  • Set MinVersion: tls.VersionTLS12 or later in crypto/tls's tls.Config; prefer tls.VersionTLS13 when compatible.
  • Avoid TLS 1.0/1.1 unless an exceptional legacy requirement, such as support for an old browser, remains. Isolate any necessary legacy path on a separate service or domain and consider additional monitoring and risk communication.
  • Periodically review TLS settings against organizational policy, browser/platform support, OWASP guidance, and runtime release notes.
  • Check the protocols and cipher suites accepted by the service with tools such as sslscan, nmap --script ssl-enum-ciphers, or an online TLS scanner.

Examples

Before

go
package main

import (
    "crypto/tls"
    "net/http"
)

func newInsecureServer() *http.Server {
    // MinVersion omitted: the minimum depends on Go and environment settings
    // The current default is TLS 1.2
    tlsConfig := &tls.Config{
        // Other options only; no MinVersion
        // For example, only CipherSuites or Certificates
    }

    return &http.Server{
        Addr:      ":8443",
        TLSConfig: tlsConfig,
    }
}

func main() {
    srv := newInsecureServer()
    // Example certificate and key paths
    _ = srv.ListenAndServeTLS("server.crt", "server.key")
}

After

go
package main

import (
    "crypto/tls"
    "net/http"
)

func newSecureServer() *http.Server {
    tlsConfig := &tls.Config{
        // Explicitly require TLS 1.2 or later
        MinVersion: tls.VersionTLS12,
        // Add other security settings if needed, such as cipher-suite restrictions
        // CipherSuites: []uint16{ ... },
    }

    return &http.Server{
        Addr:      ":8443",
        TLSConfig: tlsConfig,
    }
}

func main() {
    srv := newSecureServer()
    // Example certificate and key paths
    _ = srv.ListenAndServeTLS("server.crt", "server.key")
}

Explanation:

  • Before: Omitting MinVersion uses the runtime default. The current default is TLS 1.2; older Go versions and environment-specific overrides require separate checks.
  • After: MinVersion: tls.VersionTLS12 explicitly defines the minimum in code. It does not change allowed versions if the same default already applied. Also review certificate validation and the TLS 1.2 cipher suites.

References