Cloudflare Security & compliance Releases

Minimum TLS version below 1.2

Part of the Edge TLS posture check · fix arrives as a guide

What it is

The zone permits TLS versions below 1.2.

Why it matters

TLS 1.0 and 1.1 have known weaknesses and are deprecated by every major browser and by PCI DSS. Leaving them enabled means a client can negotiate down to a protocol nobody should still be using.

How to fix it

Set the minimum TLS version to 1.2 in the zone's SSL/TLS settings. Real traffic on older versions is negligible, and the ones affected are typically bots rather than browsers.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.