Your website still speaks a version of HTTPS that was retired in 2021
TLS 1.0 and 1.1 still enabled on your site? The padlock looks the same and nothing breaks. How to check your server's TLS versions and switch the old ones off.
Your website has a padlock. It has had one for years, the certificate renews itself, and when you open the site in your browser the connection details say TLS 1.3, which is as current as it gets. As far as anyone can see, the encryption side of things is finished business.
Then a customer’s supplier-onboarding questionnaire comes back with a red mark against your domain, or a card-payment scan fails, and the reason is a line nobody on your side recognises: “TLS 1.0 supported”. Nothing has been attacked. Nothing is broken. Your server has simply gone on offering two old versions of the protocol that secures HTTPS long after the rest of the world stopped using them.
This is the quiet failure: Transport Layer Security (TLS) 1.0 and 1.1 are still switched on, and because modern browsers never ask for them, nobody on your side ever sees them.
It’s more common than you’d think. In our own weekly measurement, 15.37% of websites worldwide still accept TLS 1.0 or 1.1 (n=13,510, measured 17 September 2026) — a little more than one in seven. Among UK small companies it’s 11.05% (n=733, same date), or about one in nine.
Why it stays invisible
TLS is the layer that puts the “S” in HTTPS. When a browser connects, it and the server agree on the newest version they both support, so a current browser talking to your server will pick TLS 1.3 or 1.2 every time. The old versions are never used in front of you, which means nothing you look at ever shows them. The site loads, the padlock appears, the connection details look modern.
The old versions were formally retired in March 2021, when the Internet Engineering Task Force (IETF) published RFC 8996, “Deprecating TLS 1.0 and TLS 1.1”, which moved both to Historic status because they lack support for current cryptographic algorithms. The browsers had already gone: Google removed both versions from Chrome 84, citing weak MD5 and SHA-1 hashing and flawed cipher constructions. Card payments moved even earlier — the PCI Security Standards Council set 30 June 2018 as the deadline for disabling TLS 1.0 to meet the Payment Card Industry Data Security Standard (PCI DSS).
So why is it still on? Usually because the setting was written once, years ago, and never revisited. Current nginx now defaults to TLS 1.2 and 1.3 only, but a config file copied from an old tutorial may list the old versions explicitly. Apache’s documented default is all -SSLv3, and “all” includes TLS 1.0 and 1.1. Hosting control panels and old load balancers carry their own settings forward. Nobody chose to leave them on; nobody chose to take them off either.
A caveat worth stating plainly: this is not an emergency. Because every current browser refuses TLS 1.0 and 1.1, your visitors aren’t using them, and a modern client can’t be tricked into dropping to a version it no longer speaks. The practical risk sits in three places: any genuinely old client (an ageing device, an embedded system, an old integration) that will happily connect over a weak protocol; compliance scans and security questionnaires, which fail you for it automatically; and what it signals. A server still offering 2006-era protocols is a server whose configuration nobody has looked at in a while, and anyone assessing you — a customer, an insurer, an attacker choosing targets — reads it that way.
Find it yourself
You can’t check this from your browser, precisely because your browser won’t try. You need something that tests from the outside and asks for each version in turn. Ten minutes, no installation.
- Go to the free Qualys SSL Labs Server Test.
- Type your website’s hostname (for example
www.yourcompany.co.uk) and tick Do not show the results on the boards if you’d rather it didn’t appear on the public list. Start the test. - Wait a minute or two. If your site sits behind several servers, you’ll see a list of IP addresses; click the first.
- Scroll to the Configuration section and find Protocols. It lists TLS 1.3, 1.2, 1.1 and 1.0 with a Yes or No beside each. You want No against both TLS 1.1 and TLS 1.0.
- Repeat for any other hostnames you run over HTTPS — the shop, the client portal, the webmail address. They’re often served by different kit with different settings.
Prefer the command line? From a terminal, try forcing each old version:
openssl s_client -connect www.yourcompany.co.uk:443 -tls1
openssl s_client -connect www.yourcompany.co.uk:443 -tls1_1
If a certificate and a completed handshake come back, that version is enabled. If you get an error, it may be off — but be careful, because current OpenSSL builds often refuse to offer these versions themselves, so the failure can be your end rather than the server’s. Adding -cipher 'DEFAULT@SECLEVEL=0' sometimes coaxes them into trying. If your local tools won’t cooperate, trust the SSL Labs result instead; it tests from a server built to ask.
No access to the server at all? Run the SSL Labs test anyway — it only needs the address — and send the Protocols section to whoever hosts your site, asking them to disable TLS 1.0 and 1.1.
The fix
The fix is a single setting in most places. The only real work is making sure nothing still depends on the old versions before you switch them off.
Check for anything old first. Think about what connects to your site or services that isn’t a browser: a card terminal or till system, an old accounting package that pushes data to your web server, a partner’s integration built a decade ago, a monitoring tool on an ancient appliance. If you have server access logs that record the TLS version, a week of them will tell you whether anyone is still arriving over 1.0 or 1.1. If something is, update it or talk to its supplier before you change the server, so that the fix doesn’t quietly stop the orders coming in.
If you’re behind Cloudflare, go to the Edge Certificates page under SSL/TLS in the dashboard and set Minimum TLS Version to TLS 1.2. According to Cloudflare’s documentation, this is available on every plan, including Free, and rejects anything older than the version you choose. Note their caveat that it doesn’t apply to Cloudflare Pages hostnames or R2 custom domains, which have their own settings.
If you run nginx, set this in each server block that listens on 443 (or once at the http level):
ssl_protocols TLSv1.2 TLSv1.3;
If you run Apache, replace any existing SSLProtocol line with:
SSLProtocol -all +TLSv1.2 +TLSv1.3
Reload the web server afterwards, and look for the same setting in every virtual host, since an older line lower down can override the one you just changed.
If your host or a control panel manages it, look for a “minimum TLS version” or “SSL protocols” option; failing that, ask support to set the minimum to TLS 1.2. It’s a routine request.
Confirm it stuck. Re-run the SSL Labs test and check that TLS 1.0 and 1.1 now read No. Then add the test to whatever you do once a year anyway — the certificate renewal, the insurance form — because a server migration or a restored backup is exactly the sort of thing that brings an old config back.
Once the old versions are off, your padlock means precisely what it always appeared to mean, and the next questionnaire has one fewer red mark on it. Of all the settings on your server, this is one of the few where the modern choice is also the default you’d get if you started again today.
Read next
One real, fixable exposure every week. Free.