Cloudflare
Security & compliance
Releases
Minimum TLS version below 1.2
Part of the Edge TLS posture check · fix arrives as a guide
What it is
The zone permits TLS versions below 1.2.
Why it matters
TLS 1.0 and 1.1 have known weaknesses and are deprecated by every major browser and by PCI DSS. Leaving them enabled means a client can negotiate down to a protocol nobody should still be using.
How to fix it
Set the minimum TLS version to 1.2 in the zone's SSL/TLS settings. Real traffic on older versions is negligible, and the ones affected are typically bots rather than browsers.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.