TLS versions at a glance
| Version | Status |
|---|---|
| TLS 1.3 | Recommended — fastest handshake, strongest security |
| TLS 1.2 | Secure and still required for older clients |
| TLS 1.1 | Deprecated (RFC 8996) — disable |
| TLS 1.0 | Deprecated (RFC 8996) — disable |
How the test works
The checker opens a separate connection to port 443 for each version, offering only that version, and records whether the server accepts it and which cipher it chooses.
Disabling old versions
- nginx:
ssl_protocols TLSv1.2 TLSv1.3; - Apache:
SSLProtocol -all +TLSv1.2 +TLSv1.3 - CDNs: set the minimum TLS version to 1.2 in the dashboard.
Check the certificate itself with the SSL Certificate Checker.
Frequently asked questions
Why should TLS 1.0 and 1.1 be disabled?
They have known weaknesses, all modern browsers have dropped them, and PCI DSS compliance does not allow them.
Will disabling TLS 1.0 break anything?
Only very old clients such as Android 4.3 or Internet Explorer on Windows XP are affected.
Is TLS the same as SSL?
TLS replaced SSL. People still say "SSL certificate", but modern HTTPS always uses TLS.

