TLS protocol and certificate validation settings

Review TLS protocol selection and certificate validation.

Description

Do not use obsolete protocols such as SSL or TLS 1.0 and 1.1. Use a secure TLS 1.2 or TLS 1.3 configuration, preferring TLS 1.3 where possible. Protocol selection must be accompanied by certificate-chain and hostname validation.

Potential impact

  • Data exposure: Weak protocol configurations may allow encrypted information to be compromised.
  • Man-in-the-middle attacks: An attacker may intercept or modify communication.

Remediation

  • Require at least TLS 1.2 and use TLS 1.3 when requirements and compatibility permit.
  • Clients must verify the trusted CA chain and hostname. Servers need a server context and the appropriate certificate and private key.

Examples

Before

python
# Generic context without peer verification
import ssl
import socket

context = ssl.SSLContext(ssl.PROTOCOL_SSLv23)
with socket.create_connection(('example.com', 443)) as sock:
    with context.wrap_socket(sock, server_hostname='example.com') as ssock:
        print(ssock.version())

After

python
# Client TLS with certificate and hostname validation
import ssl
import socket

context = ssl.create_default_context()
context.minimum_version = ssl.TLSVersion.TLSv1_2
with socket.create_connection(('example.com', 443)) as sock:
    with context.wrap_socket(sock, server_hostname='example.com') as ssock:
        print(ssock.version())

Explanation

  • Before: PROTOCOL_SSLv23 is an old name for a generic TLS context. Its name alone does not establish that SSL is used, but this code does not configure certificate or hostname verification. Available protocol versions depend on Python, OpenSSL and the settings.

  • After: create_default_context() enables server-certificate and hostname verification, and the minimum TLS version is explicitly set to 1.2.

  • You can require TLS 1.3 exclusively as below. This is a context-configuration excerpt: load trusted CAs before making a connection and confirm that both peers support TLS 1.3.

    python
    client_context = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
    client_context.minimum_version = ssl.TLSVersion.TLSv1_3
    client_context.maximum_version = ssl.TLSVersion.TLSv1_3
    

References