The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →To enable TLS 1.3, both ends of the HTTPS connection must support it. On Apache, use a compatible httpd release with OpenSSL 1.1.1 or newer and set SSLProtocol TLSv1.2 TLSv1.3 (or TLS 1.3 only). On Nginx, use a build containing ngx_http_ssl_module, linked to a TLS 1.3-capable OpenSSL, and set ssl_protocols TLSv1.2 TLSv1.3;. On Cloudflare, turn on SSL/TLS → Edge Certificates → TLS 1.3 or set the zone API value tls_1_3 to on. Then verify the negotiated protocol from a TLS 1.3-capable client and test both Cloudflare’s edge and your origin.
What “enable TLS 1.3” actually changes
TLS terminates wherever the HTTPS handshake is completed. With a direct Apache or Nginx deployment, your web server and its cryptographic library terminate TLS. With a proxied Cloudflare site, the browser-to-Cloudflare connection terminates at Cloudflare, while Cloudflare separately connects to your origin. These are two TLS sessions and can have different protocol settings, certificates and failures.
TLS 1.3 is therefore not enabled by changing a certificate file alone. Check the application version, the linked OpenSSL version and the active virtual-host or server configuration.
| Platform | Where TLS terminates | Configuration surface | Minimum requirement stated in the documentation | How TLS 1.3 is selected |
|---|---|---|---|---|
| Apache HTTP Server | Apache on your origin | SSLProtocol in server or virtual-host configuration |
Apache 2.4.43 or newer with OpenSSL 1.1.1 or newer for TLS 1.3 web serving | SSLProtocol TLSv1.2 TLSv1.3 or SSLProtocol TLSv1.3 |
| Nginx | Nginx on your origin | ssl_protocols in an HTTPS server block |
HTTPS support from ngx_http_ssl_module, linked to an OpenSSL release that supports TLS 1.3 |
ssl_protocols TLSv1.2 TLSv1.3; |
| Cloudflare | Cloudflare edge; optionally a second TLS session to your origin | Dashboard setting or zone API value | Available on Free, Pro, Business and Enterprise plans | Edge Certificates → TLS 1.3, or tls_1_3=on |
Enable TLS 1.3 in Apache
1. Confirm Apache and OpenSSL versions
The Apache HTTP Server project requires version 2.4.43 or newer to operate a TLS 1.3 web server with OpenSSL 1.1.1. Check both components on the machine that actually terminates HTTPS:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
httpd -v
apachectl -V
openssl version -a
Distribution commands may be named apache2 rather than httpd. The important checks are the effective Apache version and the OpenSSL library used by that binary, not merely a newer OpenSSL executable installed elsewhere.
2. Put the protocol directive in the active HTTPS virtual host
<VirtualHost *:443>
ServerName example.com
SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem
SSLProtocol TLSv1.2 TLSv1.3
</VirtualHost>
SSLProtocol is valid in server and virtual-host contexts. Keeping TLS 1.2 beside TLS 1.3 is the safer compatibility policy when you still serve older clients or integrations. Use SSLProtocol TLSv1.3 only after you have established that every intended client and upstream integration supports TLS 1.3.
3. Validate and reload without dropping existing connections
apachectl configtest
# Debian/Ubuntu examples
sudo systemctl reload apache2
# RHEL-family examples
sudo systemctl reload httpd
If the syntax test reports an unknown protocol, inspect the OpenSSL library linked to Apache and the loaded mod_ssl; a newer command-line OpenSSL does not upgrade an already-built Apache binary.
4. Name-based virtual hosts and SNI
Apache 2.4.42 and later can honor different protocol settings per name-based virtual host when built with OpenSSL 1.1.1 or newer and the client supplies SNI. A client without SNI can therefore receive the default virtual host’s policy, so test every hostname with an explicit -servername value.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteEnable TLS 1.3 in Nginx
1. Verify the HTTPS module and linked OpenSSL
The ngx_http_ssl_module is not built by default. Nginx needs that module (normally enabled with --with-http_ssl_module) and an OpenSSL library that supports TLS 1.3.
nginx -V 2>&1
openssl version -a
Read the nginx -V output for the SSL module build option and confirm that the package’s linked cryptographic library, rather than an unrelated system binary, supports TLS 1.3.
2. Set ssl_protocols in the TLS server block
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
}
The Nginx HTTPS guide documents this shape. Nginx 1.27.3 and later default to TLSv1.2 and TLSv1.3 when the linked OpenSSL supports them, but declaring the policy explicitly makes configuration reviews and older installations less ambiguous.
3. Test the parsed configuration before reloading
sudo nginx -t
sudo systemctl reload nginx
Do not reload after a failed nginx -t. Correct the file path, directive spelling, certificate permissions or module/library issue first.
4. Treat early data as a separate security decision
Nginx’s ssl_early_data on; enables TLS 1.3 early data (0-RTT) with OpenSSL 1.1.1 or newer. Requests sent in early data are subject to replay attacks. If you use it, pass $ssl_early_data to the upstream application and make non-idempotent operations reject or safely handle such requests. Enabling TLS 1.3 does not require enabling early data.
Turn on TLS 1.3 in Cloudflare
Dashboard method
- Sign in to Cloudflare and select the zone.
- Open SSL/TLS.
- Choose Edge Certificates.
- Find TLS 1.3 and switch it to On.
Cloudflare documents TLS 1.3 for Free, Pro, Business and Enterprise plans. When enabled, traffic to and from the site is served over TLS 1.3 when the client supports it. Cloudflare chooses the applicable TLS 1.3 cipher suites automatically; this zone control does not expose individual TLS 1.3 cipher selection.
API method
Cloudflare’s zone setting is named tls_1_3. Its documented values are on, zrt (Zero Round Trip Time resumption) and off. Use your normal authenticated Cloudflare zone-settings API workflow to set the value; the exact endpoint and authentication headers depend on the API client and token you use.
Choose a minimum protocol deliberately
The separate minimum-TLS control rejects visitors below the selected version. Cloudflare generally recommends TLS 1.3 for best security, but raising the minimum can break legacy clients, embedded devices and third-party integrations. Enable TLS 1.3 first, review compatibility, and only then decide whether the minimum should be raised.
Cloudflare origin settings still matter
Turning on TLS 1.3 at Cloudflare does not repair an origin that cannot complete its own HTTPS handshake. Keep the origin listening on port 443 with a valid certificate and a protocol policy compatible with Cloudflare’s connection. For an Apache or Nginx origin behind the proxy, inspect both legs:
- Client to Cloudflare: the public hostname and Cloudflare edge certificate determine the negotiated protocol.
- Cloudflare to origin: the origin’s certificate, supported protocols, SNI behavior and firewall rules determine whether Cloudflare can fetch the page.
Cloudflare’s encryption guidance also covers minimum TLS and HSTS. Do not enable HSTS until HTTPS is fully working and tested; HSTS can make an outage persistent in browsers that have cached the policy.
Should you keep TLS 1.2 enabled?
For most public sites, TLSv1.2 TLSv1.3 is the practical starting policy. TLS 1.3-only mode reduces protocol choices but excludes clients and integrations that have not implemented TLS 1.3. Inventory API clients, mobile applications, monitoring probes, payment callbacks and partner systems before removing TLS 1.2.
| Policy | Compatibility | When it fits | What to check |
|---|---|---|---|
| TLS 1.2 + TLS 1.3 | Broadest modern compatibility | General public websites and mixed client populations | Confirm both versions meet your organization’s security baseline |
| TLS 1.3 only | Restricts older clients | Controlled environments where every client is known and current | Legacy integrations, scanners, health checks and vendor callbacks |
| Cloudflare TLS 1.3 with minimum TLS unchanged | Edge negotiates TLS 1.3 when possible while preserving older-client access | Incremental rollout | Actual negotiated versions and origin connectivity |
Verify that TLS 1.3 is really being negotiated
OpenSSL protocol check
From a client with TLS 1.3 support, run:
openssl s_client -connect example.com:443 -servername example.com -tls1_3
After the handshake, look for a negotiated protocol line reporting TLSv1.3. The explicit -servername is important for SNI-based Apache and Nginx virtual hosts.
Inspect the HTTP endpoint and certificate
curl -I -v https://example.com/
The verbose output helps identify the hostname reached, certificate chain, redirects and handshake failures. It complements, rather than replaces, the protocol-specific OpenSSL check.
Test both public and origin names
- Run the checks against the public Cloudflare hostname.
- Where your architecture permits, run them against the direct origin hostname or address with the correct SNI name.
- Compare the results after certificate renewal, web-server upgrades, OpenSSL upgrades and Cloudflare setting changes.
A browser showing TLS 1.3 proves the edge connection only; it does not prove that Cloudflare’s origin connection uses the same protocol.
Rank #4
Or skip the browser setup
If you need repeatable screenshots of TLS documentation, status pages or deployment checks, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns a PNG, JPEG, WebP or PDF. Before capture it accepts the cookie or consent banner like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and every response identifies the result with X-Page-Verdict and X-Billed headers.
Use the API examples in the ScreenshotNeo documentation:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o tls-check.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
r.raise_for_status()
open("tls-check.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`HTTP ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('tls-check.webp', Buffer.from(await res.arrayBuffer()));
ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. Every feature is on every plan: full-page and element capture, device presets, custom viewport and retina scale, PDF controls, custom CSS and JavaScript, waits, request blocking, headers and cookies, geolocation and timezone, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000, and yearly billing gives two months free.
Create a free ScreenshotNeo account to start with 1,000 screenshots a month and no card.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting TLS 1.3 enablement
“Unknown protocol” or TLS 1.3 is absent from the available list
The web server is probably linked to an older OpenSSL, or the required SSL module is missing. Verify the library used by the running Apache or Nginx binary, install a supported package/build, and restart the service so it loads the new library.
Apache reload fails after adding SSLProtocol
Run apachectl configtest and inspect the exact file and virtual host reported. Check that mod_ssl is loaded, the directive is inside the intended server or virtual-host context, and certificate paths are readable by the service account.
Nginx reports an unknown ssl_protocols directive
The binary was built without ngx_http_ssl_module, or the file is being parsed by a different Nginx installation than the one you inspected. Compare the path returned by command -v nginx with nginx -V, install an SSL-enabled build, then run nginx -t again.
Best Value
- Used Book in Good Condition
Cloudflare shows TLS 1.3, but visitors see origin errors
Separate the edge handshake from the origin handshake. Check origin port 443, certificate name and chain, firewall allowlists, SNI and the origin’s protocol policy. A successful browser-to-Cloudflare TLS 1.3 handshake cannot mask a failed Cloudflare-to-origin connection.
The OpenSSL test negotiates TLS 1.2
Confirm that you used -tls1_3 and connected to the intended hostname with SNI. If that explicit test fails, inspect the active virtual host, proxy or load balancer rather than assuming the edited file is in use. If it succeeds but an application still reports TLS 1.2, that application may be using a different endpoint or connection pool.
Requests fail only after enabling early data
Disable ssl_early_data while diagnosing, or ensure the upstream receives $ssl_early_data and rejects replay-sensitive, non-idempotent requests. TLS 1.3 itself can remain enabled without 0-RTT.
Free tools Windows power users keep installed
One-click scans. No signup required.
Operational checklist
- Record the Apache/Nginx version and the OpenSSL library actually linked to it.
- Keep a tested TLS 1.2 fallback unless all clients and integrations are controlled.
- Validate configuration before every reload and monitor the service after deployment.
- Test each hostname with SNI, including the default virtual host and any aliases.
- For Cloudflare, verify both edge and origin connections.
- Delay HSTS until HTTPS, redirects, certificates and all required hostnames are working.
- Repeat protocol checks after renewals and software or Cloudflare policy changes.
FAQ
Does TLS 1.3 require a new kind of certificate?
No. TLS 1.3 still uses the server’s normal X.509 certificate and private key. The compatibility requirement is in the TLS implementation and cryptographic library, not a special certificate format.
Will enabling TLS 1.3 automatically enable HTTP/2?
No. HTTP protocol negotiation and TLS version selection are separate settings. Configure and verify HTTP/2 independently of the TLS 1.3 change.
Can a monitoring probe report a different TLS version from a browser?
Yes. Clients offer different protocol versions and cipher capabilities, and a proxy can terminate TLS at a different layer. Compare probes that target the same hostname, port and SNI name before drawing conclusions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




