{"record":{"id":"2ce05d557a82f402","repo":"gofiber/fiber","slug":"unsupported-tls-version-please-use-tls-versiontls","errorCode":null,"errorMessage":"unsupported TLS version, please use tls.VersionTLS12 or tls.VersionTLS13","messagePattern":"unsupported TLS version, please use tls\\.VersionTLS12 or tls\\.VersionTLS13","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"listen.go","lineNumber":202,"sourceCode":"\tif cfg.UnixSocketFileMode == 0 {\n\t\tcfg.UnixSocketFileMode = 0o770\n\t}\n\n\tif cfg.TLSMinVersion == 0 {\n\t\tcfg.TLSMinVersion = tls.VersionTLS12\n\t}\n\n\treturn cfg\n}\n\n// validateTLSMinVersion rejects a version this package will not build a\n// tls.Config from. Asked only where the field is read: rejecting it in the\n// defaults panicked before warnSupersededTLSFields or\n// warnIgnoredTLSFieldsOnListener could say the value was being ignored anyway,\n// which is the diagnostic a stale TLS 1.1 most needs.\nfunc validateTLSMinVersion(cfg *ListenConfig) {\n\tif cfg.TLSMinVersion != tls.VersionTLS12 && cfg.TLSMinVersion != tls.VersionTLS13 {\n\t\tpanic(\"unsupported TLS version, please use tls.VersionTLS12 or tls.VersionTLS13\")\n\t}\n}\n\n// Listen serves HTTP requests from the given addr.\n// You should enter custom ListenConfig to customize startup. (TLS, mTLS, prefork...)\n//\n//\tapp.Listen(\":8080\")\n//\tapp.Listen(\"127.0.0.1:8080\")\n//\tapp.Listen(\":8080\", ListenConfig{EnablePrefork: true})\nfunc (app *App) Listen(addr string, config ...ListenConfig) error {\n\tcfg := listenConfigDefault(config...)\n\n\t// Configure TLS\n\tvar tlsConfig *tls.Config\n\tvar tlsHandler *TLSHandler\n\tif cfg.TLSConfig != nil {\n\t\ttlsConfig = cfg.TLSConfig.Clone()\n\t\twarnSupersededTLSFields(&cfg)","sourceCodeStart":184,"sourceCodeEnd":220,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/listen.go#L184-L220","documentation":"fiber/v3 only builds a tls.Config for TLS 1.2 (tls.VersionTLS12) and TLS 1.3 (tls.VersionTLS13); older versions (TLS 1.0/1.1) and zero/garbage values are rejected. validateTLSMinVersion is intentionally called where ListenConfig is consumed (not in the defaults step) so the diagnostic coincides with the field actually being used, rather than being masked by later 'superseded/ignored' warnings. TLS 1.1 in particular is deprecated (RFC 8996) and must surface as a hard error.","triggerScenarios":"Calling app.Listen(addr, fiber.ListenConfig{ TLSConfig: &tls.Config{MinVersion: ...}, TLSMinVersion: tls.VersionTLS11 }) (or VersionTLS10, or 0, or any value other than the two accepted constants) — typically when ListenConfig.TLSMinVersion is set explicitly.","commonSituations":"Migrating from fiber v2 or an older codebase that pinned TLS 1.0/1.1 for legacy clients; setting MinVersion on the *tls.Config but also setting TLSMinVersion on ListenConfig to a deprecated value; copying a tutorial that hardcodes an old constant; leaving TLSMinVersion unset on a struct that was initialized with a stale zero/low value via reflection or config loader.","solutions":["Set ListenConfig.TLSMinVersion to tls.VersionTLS12 (minimum) or tls.VersionTLS13.","Ensure the *tls.Config.MinVersion passed via TLSConfig is also one of those two values.","Remove legacy TLS 1.0/1.1 pins and test affected legacy clients against TLS 1.2 with a compatible cipher suite."],"exampleFix":"// before\napp.Listen(\":443\", fiber.ListenConfig{\n    TLSMinVersion: tls.VersionTLS11,\n})\n// after\napp.Listen(\":443\", fiber.ListenConfig{\n    TLSMinVersion: tls.VersionTLS12, // or VersionTLS13\n})","handlingStrategy":"validation","validationCode":"func validTLSMin(v uint16) bool {\n    return v == tls.VersionTLS12 || v == tls.VersionTLS13\n}\n\nif !validTLSMin(cfg.TLSMinVersion) {\n    return fmt.Errorf(\"unsupported TLSMinVersion 0x%x; use TLS1.2 or TLS1.3\", cfg.TLSMinVersion)\n}\napp.Listen(\":443\", cfg)","typeGuard":null,"tryCatchPattern":"defer func() {\n    if r := recover(); r != nil {\n        log.Fatalf(\"TLS config rejected: %v\", r)\n    }\n}()\napp.Listen(\":443\", cfg)","preventionTips":["Pin TLSMinVersion to tls.VersionTLS13 (or at least tls.VersionTLS12) in config defaults.","Reject TLS 1.0/1.1 in config loaders and code review; they are deprecated (RFC 8996).","Add a startup self-test that asserts the effective MinVersion is one of the two allowed constants."],"tags":["tls","security","listen","startup","deprecation"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}