Description
Allowing older protocols such as TLS 1.0/1.1 can weaken transport protection. However, current Go crypto/tls defaults to TLS 1.2 when MinVersion is omitted, so omission alone does not establish an insecure connection. Check the deployed Go version and environment settings, and specify the minimum TLS version required by the service.
Potential impact
- Negotiating an old protocol or weak cipher suite can reduce the confidentiality and integrity of sensitive information.
- Unchecked runtime defaults or exception settings may differ from the organization's required minimum.
- An unnecessarily high minimum can also disconnect required clients, so check compatibility during migration.
Remediation
- Set
MinVersion: tls.VersionTLS12or later incrypto/tls'stls.Config; prefertls.VersionTLS13when compatible. - Avoid TLS 1.0/1.1 unless an exceptional legacy requirement, such as support for an old browser, remains. Isolate any necessary legacy path on a separate service or domain and consider additional monitoring and risk communication.
- Periodically review TLS settings against organizational policy, browser/platform support, OWASP guidance, and runtime release notes.
- Check the protocols and cipher suites accepted by the service with tools such as
sslscan,nmap --script ssl-enum-ciphers, or an online TLS scanner.
Examples
Before
go
package main
import (
"crypto/tls"
"net/http"
)
func newInsecureServer() *http.Server {
// MinVersion omitted: the minimum depends on Go and environment settings
// The current default is TLS 1.2
tlsConfig := &tls.Config{
// Other options only; no MinVersion
// For example, only CipherSuites or Certificates
}
return &http.Server{
Addr: ":8443",
TLSConfig: tlsConfig,
}
}
func main() {
srv := newInsecureServer()
// Example certificate and key paths
_ = srv.ListenAndServeTLS("server.crt", "server.key")
}
After
go
package main
import (
"crypto/tls"
"net/http"
)
func newSecureServer() *http.Server {
tlsConfig := &tls.Config{
// Explicitly require TLS 1.2 or later
MinVersion: tls.VersionTLS12,
// Add other security settings if needed, such as cipher-suite restrictions
// CipherSuites: []uint16{ ... },
}
return &http.Server{
Addr: ":8443",
TLSConfig: tlsConfig,
}
}
func main() {
srv := newSecureServer()
// Example certificate and key paths
_ = srv.ListenAndServeTLS("server.crt", "server.key")
}
Explanation:
- Before: Omitting
MinVersionuses the runtime default. The current default is TLS 1.2; older Go versions and environment-specific overrides require separate checks. - After:
MinVersion: tls.VersionTLS12explicitly defines the minimum in code. It does not change allowed versions if the same default already applied. Also review certificate validation and the TLS 1.2 cipher suites.