Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense 2.7.2 HAProxy 2.8.3 is not allowing TLSv1.0, 1.1

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 3 Posters 817 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      anandpeculiar
      last edited by anandpeculiar

      after upgrading my pfsense from 2.7.0 to 2.7.2 my web application is stopped working due to TLSv1.0 and 1.1 is not supporting/allowing.

      i have tried below settings but still not working

      1. SSL/TLS Compatibility Mode has been set to Old in global settings

      Pfsense-SSL-Mode.png

      1. added to use tlsv1.0 and 1.1 forcefully in the Frontend setting, it allows 1.2 but not 1.0 and 1.1.

      Pfsense-SSL-Frontend-Force.png

      S 1 Reply Last reply Reply Quote 0
      • S
        slu @anandpeculiar
        last edited by

        @anandpeculiar
        not unsing HAProxy, but found this because an other SSL issue:
        https://github.com/openssl/openssl/issues/17476#issuecomment-1010812582

        pfSense Gold subscription

        1 Reply Last reply Reply Quote 0
        • A
          anandpeculiar
          last edited by anandpeculiar

          @slu , Thanks for pointing the useful information, i ended up by binding :@SECLEVEL=0 at the end of the Advanced SSL option for each frontend where i need to allow the Older TLS version
          pfsense3-2.7.2-TLSV10-IssueFixed.png

          D 1 Reply Last reply Reply Quote 1
          • D
            dleventidis @anandpeculiar
            last edited by

            Hi,

            i have the same issue but putting :@SECLEVEL=0 to ssl-default-bind-ciphers just gives me an error:

            section 'frontend' : 'crt-list' : parsing [/var/etc/haproxy_test/imap_test-994.crt_list:1]: unknown ssl keyword :@SECLEVEL=0

            is there anything i can do?

            regards

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.