# TLS1.1 disable in Fleet Server

**URL:** <https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245>\
**Category:** Elastic Agent\
**Created:** [June 11, 2024, 11:48am UTC](https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245 "2024-06-11T11:48:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thorsten\_82](https://avatars.discourse-cdn.com/v4/letter/t/3ec8ea/32.png) [@Thorsten\_82](https://discuss.elastic.co/u/Thorsten_82)\
**Post date:** [June 11, 2024, 11:48am UTC](https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245/1 "2024-06-11T11:48:04Z")

</div>

Hello,

I want do disable TLS1.1 support in Elastic Agent (Fleet Server).  
In Custom fleet-server configurations I tried to set the "ssl.supported\_protocols: [TLSv1.2]" but with no effect.  
With "elastic-agent inspect" I see the setting I have made.

```auto
- data_stream:
    namespace: default
  id: fleet-server-fleet_server-e3679c00-3110-11ee-89dc-61113427e2ab
  meta:
    package:
      name: fleet_server
      version: 1.3.1
  name: fleet_server-1
  package_policy_id: e3679c00-3110-11ee-89dc-61113427e2ab
  revision: 5
  ssl:
    supported_protocols:
    - TLSv1.3
  type: fleet-server
  unused_key: not_used
  use_output: default

```

But with openssl s\_client I am still able to connect with TLS1.1.

```auto
SSL handshake has read 2887 bytes and written 262 bytes
Verification: OK
---
New, TLSv1.0, Cipher is ECDHE-RSA-AES128-SHA
Server public key is 4096 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol : TLSv1.1
    Cipher : ECDHE-RSA-AES128-SHA
    Session-ID: 81D4516E1C3E2AD777764D779D9C106A19A66ECB6BFF47904F554314658EA221
    Session-ID-ctx:

```

Can anyone help me?

Thanks!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 11, 2024, 2:27pm UTC](https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245/2 "2024-06-11T14:27:27Z")

</div>

> [@Thorsten\_82](#):
>
> In Custom fleet-server configurations I tried to set the "ssl.supported\_protocols: [TLSv1.2]" but with no effect

You need to use `server.ssl.supported_protocols`.

I have this on mine:

```auto
server.ssl.supported_protocols: ["TLSv1.2", "TLSv1.3"]
server.ssl.cipher_suites: ["ECDHE-RSA-AES-128-GCM-SHA256", "ECDHE-RSA-AES-256-GCM-SHA384", "ECDHE-RSA-AES-128-CBC-SHA", "ECDHE-RSA-AES-256-CBC-SHA", "RSA-AES-128-GCM-SHA256", "RSA-AES-256-GCM-SHA384", "RSA-AES-128-CBC-SHA", "RSA-AES-256-CBC-SHA"]

```

---

<div class="post-metadata">

**Author:** ![Thorsten\_82](https://avatars.discourse-cdn.com/v4/letter/t/3ec8ea/32.png) [@Thorsten\_82](https://discuss.elastic.co/u/Thorsten_82)\
**Post date:** [June 12, 2024, 6:30am UTC](https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245/3 "2024-06-12T06:30:44Z")

</div>

Hey,

thanks a lot. That solved my issue!
