# TLS1.1 disable in Fleet Server

**URL:** <https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245>\
**Category:** Elastic Agent\
**Created:** [June 11, 2024, 11:48am UTC](https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245 "2024-06-11T11:48:04Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 11, 2024, 2:27pm UTC](https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245/2 "2024-06-11T14:27:27Z")

</div>

> [@Thorsten\_82](#):
>
> In Custom fleet-server configurations I tried to set the "ssl.supported\_protocols: [TLSv1.2]" but with no effect

You need to use `server.ssl.supported_protocols`.

I have this on mine:

```auto
server.ssl.supported_protocols: ["TLSv1.2", "TLSv1.3"]
server.ssl.cipher_suites: ["ECDHE-RSA-AES-128-GCM-SHA256", "ECDHE-RSA-AES-256-GCM-SHA384", "ECDHE-RSA-AES-128-CBC-SHA", "ECDHE-RSA-AES-256-CBC-SHA", "RSA-AES-128-GCM-SHA256", "RSA-AES-256-GCM-SHA384", "RSA-AES-128-CBC-SHA", "RSA-AES-256-CBC-SHA"]

```

---

_[View the full topic](https://discuss.elastic.co/t/tls1-1-disable-in-fleet-server/361245)._
