Description
Do not use obsolete protocols such as SSL or TLS 1.0 and 1.1. Use a secure TLS 1.2 or TLS 1.3 configuration, preferring TLS 1.3 where possible. Protocol selection must be accompanied by certificate-chain and hostname validation.
Potential impact
- Data exposure: Weak protocol configurations may allow encrypted information to be compromised.
- Man-in-the-middle attacks: An attacker may intercept or modify communication.
Remediation
- Require at least TLS 1.2 and use TLS 1.3 when requirements and compatibility permit.
- Clients must verify the trusted CA chain and hostname. Servers need a server context and the appropriate certificate and private key.
Examples
Before
# Generic context without peer verification
import ssl
import socket
context = ssl.SSLContext(ssl.PROTOCOL_SSLv23)
with socket.create_connection(('example.com', 443)) as sock:
with context.wrap_socket(sock, server_hostname='example.com') as ssock:
print(ssock.version())
After
# Client TLS with certificate and hostname validation
import ssl
import socket
context = ssl.create_default_context()
context.minimum_version = ssl.TLSVersion.TLSv1_2
with socket.create_connection(('example.com', 443)) as sock:
with context.wrap_socket(sock, server_hostname='example.com') as ssock:
print(ssock.version())
Explanation
-
Before:
PROTOCOL_SSLv23is an old name for a generic TLS context. Its name alone does not establish that SSL is used, but this code does not configure certificate or hostname verification. Available protocol versions depend on Python, OpenSSL and the settings. -
After:
create_default_context()enables server-certificate and hostname verification, and the minimum TLS version is explicitly set to 1.2. -
You can require TLS 1.3 exclusively as below. This is a context-configuration excerpt: load trusted CAs before making a connection and confirm that both peers support TLS 1.3.
pythonclient_context = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT) client_context.minimum_version = ssl.TLSVersion.TLSv1_3 client_context.maximum_version = ssl.TLSVersion.TLSv1_3