Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
Apache

How to Enable TLS 1.3 in Apache, Nginx, and Cloudflare

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To enable TLS 1.3, both ends of the HTTPS connection must support it. On Apache, use a compatible httpd release with OpenSSL 1.1.1 or newer and set SSLProtocol TLSv1.2 TLSv1.3 (or TLS 1.3 only). On Nginx, use a build containing ngx_http_ssl_module, linked to a TLS 1.3-capable OpenSSL, and set ssl_protocols TLSv1.2 TLSv1.3;. On Cloudflare, turn on SSL/TLS → Edge Certificates → TLS 1.3 or set the zone API value tls_1_3 to on. Then verify the negotiated protocol from a TLS 1.3-capable client and test both Cloudflare’s edge and your origin.

What “enable TLS 1.3” actually changes

TLS terminates wherever the HTTPS handshake is completed. With a direct Apache or Nginx deployment, your web server and its cryptographic library terminate TLS. With a proxied Cloudflare site, the browser-to-Cloudflare connection terminates at Cloudflare, while Cloudflare separately connects to your origin. These are two TLS sessions and can have different protocol settings, certificates and failures.

TLS 1.3 is therefore not enabled by changing a certificate file alone. Check the application version, the linked OpenSSL version and the active virtual-host or server configuration.

Platform Where TLS terminates Configuration surface Minimum requirement stated in the documentation How TLS 1.3 is selected
Apache HTTP Server Apache on your origin SSLProtocol in server or virtual-host configuration Apache 2.4.43 or newer with OpenSSL 1.1.1 or newer for TLS 1.3 web serving SSLProtocol TLSv1.2 TLSv1.3 or SSLProtocol TLSv1.3
Nginx Nginx on your origin ssl_protocols in an HTTPS server block HTTPS support from ngx_http_ssl_module, linked to an OpenSSL release that supports TLS 1.3 ssl_protocols TLSv1.2 TLSv1.3;
Cloudflare Cloudflare edge; optionally a second TLS session to your origin Dashboard setting or zone API value Available on Free, Pro, Business and Enterprise plans Edge Certificates → TLS 1.3, or tls_1_3=on

Enable TLS 1.3 in Apache

1. Confirm Apache and OpenSSL versions

The Apache HTTP Server project requires version 2.4.43 or newer to operate a TLS 1.3 web server with OpenSSL 1.1.1. Check both components on the machine that actually terminates HTTPS:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
httpd -v
apachectl -V
openssl version -a

Distribution commands may be named apache2 rather than httpd. The important checks are the effective Apache version and the OpenSSL library used by that binary, not merely a newer OpenSSL executable installed elsewhere.

2. Put the protocol directive in the active HTTPS virtual host

<VirtualHost *:443>
    ServerName example.com
    SSLEngine on
    SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem
    SSLProtocol TLSv1.2 TLSv1.3
</VirtualHost>

SSLProtocol is valid in server and virtual-host contexts. Keeping TLS 1.2 beside TLS 1.3 is the safer compatibility policy when you still serve older clients or integrations. Use SSLProtocol TLSv1.3 only after you have established that every intended client and upstream integration supports TLS 1.3.

3. Validate and reload without dropping existing connections

apachectl configtest
# Debian/Ubuntu examples
sudo systemctl reload apache2
# RHEL-family examples
sudo systemctl reload httpd

If the syntax test reports an unknown protocol, inspect the OpenSSL library linked to Apache and the loaded mod_ssl; a newer command-line OpenSSL does not upgrade an already-built Apache binary.

4. Name-based virtual hosts and SNI

Apache 2.4.42 and later can honor different protocol settings per name-based virtual host when built with OpenSSL 1.1.1 or newer and the client supplies SNI. A client without SNI can therefore receive the default virtual host’s policy, so test every hostname with an explicit -servername value.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Enable TLS 1.3 in Nginx

1. Verify the HTTPS module and linked OpenSSL

The ngx_http_ssl_module is not built by default. Nginx needs that module (normally enabled with --with-http_ssl_module) and an OpenSSL library that supports TLS 1.3.

nginx -V 2>&1
openssl version -a

Read the nginx -V output for the SSL module build option and confirm that the package’s linked cryptographic library, rather than an unrelated system binary, supports TLS 1.3.

2. Set ssl_protocols in the TLS server block

server {
    listen 443 ssl;
    server_name example.com;

    ssl_certificate     /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    ssl_protocols       TLSv1.2 TLSv1.3;
}

The Nginx HTTPS guide documents this shape. Nginx 1.27.3 and later default to TLSv1.2 and TLSv1.3 when the linked OpenSSL supports them, but declaring the policy explicitly makes configuration reviews and older installations less ambiguous.

3. Test the parsed configuration before reloading

sudo nginx -t
sudo systemctl reload nginx

Do not reload after a failed nginx -t. Correct the file path, directive spelling, certificate permissions or module/library issue first.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Treat early data as a separate security decision

Nginx’s ssl_early_data on; enables TLS 1.3 early data (0-RTT) with OpenSSL 1.1.1 or newer. Requests sent in early data are subject to replay attacks. If you use it, pass $ssl_early_data to the upstream application and make non-idempotent operations reject or safely handle such requests. Enabling TLS 1.3 does not require enabling early data.

Turn on TLS 1.3 in Cloudflare

Dashboard method

  1. Sign in to Cloudflare and select the zone.
  2. Open SSL/TLS.
  3. Choose Edge Certificates.
  4. Find TLS 1.3 and switch it to On.

Cloudflare documents TLS 1.3 for Free, Pro, Business and Enterprise plans. When enabled, traffic to and from the site is served over TLS 1.3 when the client supports it. Cloudflare chooses the applicable TLS 1.3 cipher suites automatically; this zone control does not expose individual TLS 1.3 cipher selection.

API method

Cloudflare’s zone setting is named tls_1_3. Its documented values are on, zrt (Zero Round Trip Time resumption) and off. Use your normal authenticated Cloudflare zone-settings API workflow to set the value; the exact endpoint and authentication headers depend on the API client and token you use.

Choose a minimum protocol deliberately

The separate minimum-TLS control rejects visitors below the selected version. Cloudflare generally recommends TLS 1.3 for best security, but raising the minimum can break legacy clients, embedded devices and third-party integrations. Enable TLS 1.3 first, review compatibility, and only then decide whether the minimum should be raised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare origin settings still matter

Turning on TLS 1.3 at Cloudflare does not repair an origin that cannot complete its own HTTPS handshake. Keep the origin listening on port 443 with a valid certificate and a protocol policy compatible with Cloudflare’s connection. For an Apache or Nginx origin behind the proxy, inspect both legs:

  • Client to Cloudflare: the public hostname and Cloudflare edge certificate determine the negotiated protocol.
  • Cloudflare to origin: the origin’s certificate, supported protocols, SNI behavior and firewall rules determine whether Cloudflare can fetch the page.

Cloudflare’s encryption guidance also covers minimum TLS and HSTS. Do not enable HSTS until HTTPS is fully working and tested; HSTS can make an outage persistent in browsers that have cached the policy.

Should you keep TLS 1.2 enabled?

For most public sites, TLSv1.2 TLSv1.3 is the practical starting policy. TLS 1.3-only mode reduces protocol choices but excludes clients and integrations that have not implemented TLS 1.3. Inventory API clients, mobile applications, monitoring probes, payment callbacks and partner systems before removing TLS 1.2.

Policy Compatibility When it fits What to check
TLS 1.2 + TLS 1.3 Broadest modern compatibility General public websites and mixed client populations Confirm both versions meet your organization’s security baseline
TLS 1.3 only Restricts older clients Controlled environments where every client is known and current Legacy integrations, scanners, health checks and vendor callbacks
Cloudflare TLS 1.3 with minimum TLS unchanged Edge negotiates TLS 1.3 when possible while preserving older-client access Incremental rollout Actual negotiated versions and origin connectivity

Verify that TLS 1.3 is really being negotiated

OpenSSL protocol check

From a client with TLS 1.3 support, run:

openssl s_client -connect example.com:443 -servername example.com -tls1_3

After the handshake, look for a negotiated protocol line reporting TLSv1.3. The explicit -servername is important for SNI-based Apache and Nginx virtual hosts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect the HTTP endpoint and certificate

curl -I -v https://example.com/

The verbose output helps identify the hostname reached, certificate chain, redirects and handshake failures. It complements, rather than replaces, the protocol-specific OpenSSL check.

Test both public and origin names

  • Run the checks against the public Cloudflare hostname.
  • Where your architecture permits, run them against the direct origin hostname or address with the correct SNI name.
  • Compare the results after certificate renewal, web-server upgrades, OpenSSL upgrades and Cloudflare setting changes.

A browser showing TLS 1.3 proves the edge connection only; it does not prove that Cloudflare’s origin connection uses the same protocol.

Or skip the browser setup

If you need repeatable screenshots of TLS documentation, status pages or deployment checks, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns a PNG, JPEG, WebP or PDF. Before capture it accepts the cookie or consent banner like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and every response identifies the result with X-Page-Verdict and X-Billed headers.

Use the API examples in the ScreenshotNeo documentation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o tls-check.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
r.raise_for_status()
open("tls-check.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`HTTP ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('tls-check.webp', Buffer.from(await res.arrayBuffer()));

ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. Every feature is on every plan: full-page and element capture, device presets, custom viewport and retina scale, PDF controls, custom CSS and JavaScript, waits, request blocking, headers and cookies, geolocation and timezone, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000, and yearly billing gives two months free.

Create a free ScreenshotNeo account to start with 1,000 screenshots a month and no card.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting TLS 1.3 enablement

“Unknown protocol” or TLS 1.3 is absent from the available list

The web server is probably linked to an older OpenSSL, or the required SSL module is missing. Verify the library used by the running Apache or Nginx binary, install a supported package/build, and restart the service so it loads the new library.

Apache reload fails after adding SSLProtocol

Run apachectl configtest and inspect the exact file and virtual host reported. Check that mod_ssl is loaded, the directive is inside the intended server or virtual-host context, and certificate paths are readable by the service account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nginx reports an unknown ssl_protocols directive

The binary was built without ngx_http_ssl_module, or the file is being parsed by a different Nginx installation than the one you inspected. Compare the path returned by command -v nginx with nginx -V, install an SSL-enabled build, then run nginx -t again.

Cloudflare shows TLS 1.3, but visitors see origin errors

Separate the edge handshake from the origin handshake. Check origin port 443, certificate name and chain, firewall allowlists, SNI and the origin’s protocol policy. A successful browser-to-Cloudflare TLS 1.3 handshake cannot mask a failed Cloudflare-to-origin connection.

The OpenSSL test negotiates TLS 1.2

Confirm that you used -tls1_3 and connected to the intended hostname with SNI. If that explicit test fails, inspect the active virtual host, proxy or load balancer rather than assuming the edited file is in use. If it succeeds but an application still reports TLS 1.2, that application may be using a different endpoint or connection pool.

Requests fail only after enabling early data

Disable ssl_early_data while diagnosing, or ensure the upstream receives $ssl_early_data and rejects replay-sensitive, non-idempotent requests. TLS 1.3 itself can remain enabled without 0-RTT.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operational checklist

  • Record the Apache/Nginx version and the OpenSSL library actually linked to it.
  • Keep a tested TLS 1.2 fallback unless all clients and integrations are controlled.
  • Validate configuration before every reload and monitor the service after deployment.
  • Test each hostname with SNI, including the default virtual host and any aliases.
  • For Cloudflare, verify both edge and origin connections.
  • Delay HSTS until HTTPS, redirects, certificates and all required hostnames are working.
  • Repeat protocol checks after renewals and software or Cloudflare policy changes.

FAQ

Does TLS 1.3 require a new kind of certificate?

No. TLS 1.3 still uses the server’s normal X.509 certificate and private key. The compatibility requirement is in the TLS implementation and cryptographic library, not a special certificate format.

Will enabling TLS 1.3 automatically enable HTTP/2?

No. HTTP protocol negotiation and TLS version selection are separate settings. Configure and verify HTTP/2 independently of the TLS 1.3 change.

Can a monitoring probe report a different TLS version from a browser?

Yes. Clients offer different protocol versions and cipher capabilities, and a proxy can terminate TLS at a different layer. Compare probes that target the same hostname, port and SNI name before drawing conclusions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.