How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (2024)

by InMotion Hosting Contributor

2 Minutes, 46 Seconds to Read

How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (1)

TLS versions 1.0 and 1.1 are now considered insecure with TLS 1.2 being the current standard and TLS 1.3 being the newest version available today. However, many web server environments leave the older TLS versions enabled to ensure compatibility for new users. This is a quick, but valuable way to harden your Linux server to protect your data and website visitors.

See Also
.MY | MYNIC

To test what TLS versions your Linux web server uses, you can use third party tools such as the Qualys SSL Labs online tool, included in the Mozilla Observatory Header Scanner.

Below we cover how to disable older TLS versions and enable TLS 1.3 on:

  • cPanel VPS/Dedicated Servers
  • Nginx Servers
  • Apache Servers

Disable TLS 1.0 and TLS 1.1 in cPanel

  1. Log into WebHost Manager (WHM) as root.
  2. On the left, select Apache Configuration.
  3. Select Global Configuration.
  4. Beside SSL/TLS Protocols. you’ll likely see text similar to the following: SSLv23:!SSLv2:!SSLv3:!TLSv1:!TLSv1_1. Select the radio button beside “TLSv1.2default.” If you wish to support the latest TLS version, TLS 1.3, select the radio button beside the text field and type the following:
    TLSv1.2 +TLSv1.3 
    How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (2)
  5. At the bottom, select Save.
  6. Select Rebuild Configuration and Restart Apache.
  7. If your cPanel server runs Nginx, follow the Nginx section below. If not, test your TLS settings.

How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (3)Enjoy high-performance, lightning-fast servers with increased security and maximum up-time with our Secure VPS Hosting!

How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (4)Linux VPS How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (5)cPanel or Control Web Panel How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (6)Scalable How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (7)Website Migration Assistance

Linux VPS Hosting

Disable Older TLS Versions on Nginx Servers

If your cPanel server runs Nginx, including users with the cPanel Cache Manager, you’ll need to do some advanced Nginx configuration:

Steps may differ if not managing an InMotion Hosting server.

  1. Log into SSH or WHM Terminal as root.
  2. Edit your default Nginx configuration file:
    nano /opt/ngxconf/templates/default_server.j2
  3. Look for the ssl_protocols line at the bottom of the file. Remove TLSv1.1.
  4. Save changes.
  5. Rebuild your Nginx configuration:
    ngxconf -Rrd --force
  6. Purge your Nginx cache:
    ngxutil -Z
  7. Test your TLS settings.

Disable Older TLS Versions on Apache Servers

Follow these steps to harden unmanged Linux servers.

  1. SSH into your server as root.
  2. Edit your Apache configuration file. You can use the find command if it’s not below:

    CentOS:

    nano /etc/httpd/conf.d
    Debian/Ubuntu:
    nano /etc/apache2/mods-enabled/ssl.conf

    find / -iname ssl.conf
  3. Edit the SSLProtocol line. Ensure it states the following:
    SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
  4. Save changes.
  5. Restart Apache:
    systemctl restart apache2
  6. Test your TLS settings.

If you don’t need cPanel, don't pay for it. Only pay for what you need with our scalable Cloud VPS Hosting.

How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (8)CentOS, Debian, or Ubuntu How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (9)No Bloatware How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (10)SSH and Root Access

Test your SSL/TLS Settings

After you finish configuring your TLS settings, there are two easy methods to check your TLS changes.

The easiest option is to use the Qualys SSL Labs test. Make sure to check the box stating “Do not show the results on the boards” for some anonymity.

  • At the top, you should not see “This server supports TLS 1.0 and TLS 1.1.
  • If you enabled TLS 1.3, you should see “This server supports TLS 1.3” in green.
  • View the related cPanel forum threads for more information on how to support Forward Secrecy.
  • If you have a CAA DNS record, you’ll also see “DNS Certification Authority Authorization (CAA) Policy found for this domain.”

For terminal users with Nmap installed, you can use it or the Zenmap graphical application to check for insecure TLS ciphers.

nmap --script ssl-enum-ciphers -p 443 YourDomain.com

Be sure to bookmark our guide onVPS Security to learn more ways to protect your server. Have any questions about disabling older TLS protocols or SSL certificates? Let us know in our Community Forum.

How to Disable Older TLS Versions in Apache and Nginx | InMotion Hosting (2024)
Top Articles
Volume Flutter
Adi Shamir Invented the RSA Algorithm for Securing Communication
Netronline Taxes
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Pieology Nutrition Calculator Mobile
Greedfall Console Commands
The Atlanta Constitution from Atlanta, Georgia
Manhattan Prep Lsat Forum
Jailbase Orlando
10 Popular Hair Growth Products Made With Dermatologist-Approved Ingredients to Shop at Amazon
Obituaries
Calamity Hallowed Ore
J Prince Steps Over Takeoff
Free Robux Without Downloading Apps
Turbocharged Cars
List of all the Castle's Secret Stars - Super Mario 64 Guide - IGN
Roof Top Snipers Unblocked
Axe Throwing Milford Nh
Kayky Fifa 22 Potential
Ge-Tracker Bond
Busted Campbell County
Big Lots Weekly Advertisem*nt
Never Give Up Quotes to Keep You Going
Best Transmission Service Margate
Somewhere In Queens Showtimes Near The Maple Theater
Troy Gamefarm Prices
Klsports Complex Belmont Photos
Kirk Franklin Mother Debra Jones Age
Craigslist Sf Garage Sales
Prévisions météo Paris à 15 jours - 1er site météo pour l'île-de-France
After Transmigrating, The Fat Wife Made A Comeback! Chapter 2209 – Chapter 2209: Love at First Sight - Novel Cool
About | Swan Medical Group
Here’s how you can get a foot detox at home!
Pickle Juiced 1234
Colorado Parks And Wildlife Reissue List
Admissions - New York Conservatory for Dramatic Arts
Cdcs Rochester
The Closest Walmart From My Location
Insideaveritt/Myportal
Сталь aisi 310s российский аналог
The Angel Next Door Spoils Me Rotten Gogoanime
Tripadvisor Vancouver Restaurants
Citibank Branch Locations In North Carolina
Strange World Showtimes Near Century Stadium 25 And Xd
Oklahoma City Farm & Garden Craigslist
Skyward Cahokia
Euro area international trade in goods surplus €21.2 bn
Dineren en overnachten in Boutique Hotel The Church in Arnhem - Priya Loves Food & Travel
Mlb Hitting Streak Record Holder Crossword Clue
Les BABAS EXOTIQUES façon Amaury Guichon
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 5613

Rating: 4.1 / 5 (42 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.