Weak SSL and TLS protocol configuration¶
Transport security depends on the permitted protocol versions, cipher configuration, certificates and actual connection behavior. An HTTPS URL alone does not establish that all of these are correct. SSL and obsolete TLS configurations should not be kept as a general compatibility fallback.
The IETF's RFC 8996 deprecates TLS 1.0 and TLS 1.1. Use a maintained runtime and a policy that supports current TLS versions appropriate to your environment, commonly TLS 1.2 and TLS 1.3, without weakening certificate validation to make connections succeed.
Keep a suitable minimum version¶
These alternatives create a Python client SSL context. Pass the context to the actual networking client; constructing it without using it changes no connection.
Unsafe legacy policy: lower the minimum to TLS 1.0.
import ssl
context = ssl.create_default_context()
context.minimum_version = ssl.TLSVersion.TLSv1
Safer baseline: require TLS 1.2 or newer.
import ssl
context = ssl.create_default_context()
context.minimum_version = ssl.TLSVersion.TLSv1_2
The safer context retains default server-certificate and hostname validation while refusing protocols below the configured minimum. Python documents SSLContext version settings. Effective negotiation also depends on the linked TLS library, ciphers, maximum version and peer configuration; a legacy setting does not prove a particular obsolete connection actually succeeds.
Avoid disabling verification, installing accept-all callbacks or lowering cipher policy to work around an expired certificate. Fix the endpoint's certificate, hostname, trust chain or deployment compatibility instead. Protect private key material and establish a renewal process.
Check the effective connection¶
Use controlled test endpoints to confirm that a valid supported connection succeeds, an obsolete-only endpoint is refused and a hostname mismatch fails. Test the same client configuration used in deployment. Include any reverse proxy or load balancer that terminates TLS; its public policy may differ from the application's origin connection.
Continue with certificate validation, cleartext protocols and SMTP TLS. A source-level setting is one piece of evidence. Review the negotiated protocol and certificate behavior before claiming that a deployment meets its transport policy.