gofiber/fiber · critical

unsupported TLS version, please use tls.VersionTLS12 or…

Error message

unsupported TLS version, please use tls.VersionTLS12 or tls.VersionTLS13

What it means

fiber/v3 only builds a tls.Config for TLS 1.2 (tls.VersionTLS12) and TLS 1.3 (tls.VersionTLS13); older versions (TLS 1.0/1.1) and zero/garbage values are rejected. validateTLSMinVersion is intentionally called where ListenConfig is consumed (not in the defaults step) so the diagnostic coincides with the field actually being used, rather than being masked by later 'superseded/ignored' warnings. TLS 1.1 in particular is deprecated (RFC 8996) and must surface as a hard error.

Solutions

  1. Set ListenConfig.TLSMinVersion to tls.VersionTLS12 (minimum) or tls.VersionTLS13.
  2. Ensure the *tls.Config.MinVersion passed via TLSConfig is also one of those two values.
  3. Remove legacy TLS 1.0/1.1 pins and test affected legacy clients against TLS 1.2 with a compatible cipher suite.

Example fix

// before
app.Listen(":443", fiber.ListenConfig{
    TLSMinVersion: tls.VersionTLS11,
})
// after
app.Listen(":443", fiber.ListenConfig{
    TLSMinVersion: tls.VersionTLS12, // or VersionTLS13
})
Defensive patterns

Strategy: validation

Validate before calling

func validTLSMin(v uint16) bool {
    return v == tls.VersionTLS12 || v == tls.VersionTLS13
}

if !validTLSMin(cfg.TLSMinVersion) {
    return fmt.Errorf("unsupported TLSMinVersion 0x%x; use TLS1.2 or TLS1.3", cfg.TLSMinVersion)
}
app.Listen(":443", cfg)

Try / catch

defer func() {
    if r := recover(); r != nil {
        log.Fatalf("TLS config rejected: %v", r)
    }
}()
app.Listen(":443", cfg)

Prevention

When it happens

Trigger: Calling app.Listen(addr, fiber.ListenConfig{ TLSConfig: &tls.Config{MinVersion: ...}, TLSMinVersion: tls.VersionTLS11 }) (or VersionTLS10, or 0, or any value other than the two accepted constants) — typically when ListenConfig.TLSMinVersion is set explicitly.

Common situations: Migrating from fiber v2 or an older codebase that pinned TLS 1.0/1.1 for legacy clients; setting MinVersion on the *tls.Config but also setting TLSMinVersion on ListenConfig to a deprecated value; copying a tutorial that hardcodes an old constant; leaving TLSMinVersion unset on a struct that was initialized with a stale zero/low value via reflection or config loader.

Understand the failure class

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/2ce05d557a82f402. Report an issue: GitHub.

Appendix: source

Thrown at listen.go:202

	if cfg.UnixSocketFileMode == 0 {
		cfg.UnixSocketFileMode = 0o770
	}

	if cfg.TLSMinVersion == 0 {
		cfg.TLSMinVersion = tls.VersionTLS12
	}

	return cfg
}

// validateTLSMinVersion rejects a version this package will not build a
// tls.Config from. Asked only where the field is read: rejecting it in the
// defaults panicked before warnSupersededTLSFields or
// warnIgnoredTLSFieldsOnListener could say the value was being ignored anyway,
// which is the diagnostic a stale TLS 1.1 most needs.
func validateTLSMinVersion(cfg *ListenConfig) {
	if cfg.TLSMinVersion != tls.VersionTLS12 && cfg.TLSMinVersion != tls.VersionTLS13 {
		panic("unsupported TLS version, please use tls.VersionTLS12 or tls.VersionTLS13")
	}
}

// Listen serves HTTP requests from the given addr.
// You should enter custom ListenConfig to customize startup. (TLS, mTLS, prefork...)
//
//	app.Listen(":8080")
//	app.Listen("127.0.0.1:8080")
//	app.Listen(":8080", ListenConfig{EnablePrefork: true})
func (app *App) Listen(addr string, config ...ListenConfig) error {
	cfg := listenConfigDefault(config...)

	// Configure TLS
	var tlsConfig *tls.Config
	var tlsHandler *TLSHandler
	if cfg.TLSConfig != nil {
		tlsConfig = cfg.TLSConfig.Clone()
		warnSupersededTLSFields(&cfg)

View on GitHub (pinned to a105acad6c)