Legacy TLS 1.0/1.1 accepted
Check id: tls.legacy_protocols · fix effort: medium
What it means
Your server still accepts obsolete encryption protocols with known weaknesses. Raise the floor to TLS 1.2 when convenient.
The technical detail
TLS 1.0 and 1.1 are deprecated by RFC 8996 and fail compliance baselines like PCI-DSS.
How to fix it
- Set the server/load-balancer minimum to TLS 1.2.
Does your domain have this problem?
Run a free scan, takes about ten seconds.