Legacy TLS 1.0/1.1 accepted

Check id: tls.legacy_protocols · fix effort: medium

What it means

Your server still accepts obsolete encryption protocols with known weaknesses. Raise the floor to TLS 1.2 when convenient.

The technical detail

TLS 1.0 and 1.1 are deprecated by RFC 8996 and fail compliance baselines like PCI-DSS.

How to fix it

  1. Set the server/load-balancer minimum to TLS 1.2.

Does your domain have this problem?

Run a free scan, takes about ten seconds.