Skip to content

Set explicit TLS minimum version on HTTPS server - #190

Closed
AnyCPU wants to merge 1 commit into
basecamp:mainfrom
AnyCPU:fix/min_tls_version_1
Closed

AnyCPU wants to merge 1 commit into
basecamp:mainfrom
AnyCPU:fix/min_tls_version_1

Conversation

@AnyCPU

@AnyCPU AnyCPU commented Feb 15, 2026

Copy link
Copy Markdown
Contributor

The HTTPS server's tls.Config does not set MinVersion, relying on Go's runtime default (currently TLS 1.2). This default can be downgraded to TLS 1.0 via GODEBUG=tls10server=1 and could theoretically change in a future Go release.

The HTTP/3 server already sets MinVersion: tls.VersionTLS13 explicitly. This change brings the h1/h2 HTTPS server in line by setting MinVersion: tls.VersionTLS12.

@AnyCPU

AnyCPU commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

done in #251

@kevinmcconnell thanks

@AnyCPU AnyCPU closed this Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant