---
name: azion-set-the-tls-cipher-suite
description: >-
  Set the minimum TLS version and the cipher suite a workload accepts over HTTPS, from Azion Console, the Azion CLI, or the API.
---

# Set the TLS cipher suite

You can set the lowest TLS version and the cipher suite that a [workload](/en/documentation/platform/workloads/) accepts over HTTPS from Azion Console, the [Azion CLI](/en/documentation/devtools/cli/), or the API. To choose the certificate the workload presents instead, refer to [Upload a digital certificate](/en/documentation/guides/application-security/tls-and-certificates/digital-certificates/).

A cipher suite is a named set of ciphers. During the TLS handshake, the client and the workload negotiate one cipher from the suite for the session. The minimum TLS version is a floor: a client that supports only older versions cannot connect.

An account that runs on API v3 sets the minimum TLS version and the cipher suite in the Main Settings of each application instead. For more information, refer to [Main Settings](/en/documentation/platform/applications/main-settings-v3/).

---

Choose the interface you work in. The prerequisites and every procedure below switch to it.

## Prerequisites

- A workload whose deployment names an application. To create a workload and its deployment, refer to [Workloads quickstart](/en/documentation/platform/workloads/quickstart/).
- A hostname that reaches the workload over HTTPS, such as its workload domain, to check the result.

**Console**

- Access to Azion Console. For more information, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/), authorized with your account. This page matches Azion CLI 4.23.0.
- The workload ID. `azion create workload` prints it as `Created Workload with ID <workload-id>`.

**API**

- A personal token for the `Authorization` header, in the form `Token [TOKEN VALUE]`. To create a token, refer to [Personal tokens](/en/documentation/fundamentals/personal-tokens/).
- `curl` or another HTTP client.
- The workload ID. `azion create workload` prints it as `Created Workload with ID <workload-id>`.

---

## Set the minimum TLS version and the cipher suite

A new workload accepts TLS 1.3 at the lowest, `tls_1_3`, and offers suite `7`, `Modern_v2025Q1`. The minimum version takes `tls_1_0`, `tls_1_1`, `tls_1_2`, or `tls_1_3`. TLS 1.0 and TLS 1.1 are deprecated. The suite takes a number from `1` to `8`. Each number selects one named suite, and [Cipher suites](/en/documentation/platform/workloads/settings/#cipher-suites) lists the ciphers each one holds.

**Console**

To set the minimum TLS version and the cipher suite in Azion Console:

1. **Open the Workloads page**

   Access [Azion Console](https://console.azion.com/) > **Workloads**.

2. **Open the workload**

   Select the workload whose TLS settings you want to change. Azion Console opens its edit form.

3. **Turn on HTTPS support**

   In the **Protocol Settings** section, if **HTTPS support** is off, turn it on.

4. **Select the minimum TLS version**

   In **Minimum TLS version**, select the lowest TLS version the workload accepts.

5. **Select the cipher suite**

   In **Cipher suite**, select the suite the workload offers.

6. **Save the workload**

   Select **Save**.

When the update succeeds, Azion Console shows the message "Your workload has been updated".

**CLI**

To set the minimum TLS version and the cipher suite with the Azion CLI, save a JSON file with the workload ID and the `tls` object, here as `tls.json`. This file sets TLS 1.2 as the floor and suite `4`, `TLSv1.2_2021`. Keep `certificate` at the value `azion describe workload` returns for the workload, where `null` is the Azion SAN certificate:

```json
{
  "id": <workload-id>,
  "tls": {
    "certificate": null,
    "ciphers": 4,
    "minimum_version": "tls_1_2"
  }
}
```

Update the workload with the file:

```bash
azion update workload --file tls.json
```

On success, the CLI returns the workload ID:

```text
Updated Workload with ID <workload-id>
```

To confirm the change, describe the workload:

```bash
azion describe workload --workload-id <workload-id> --format json
```

The `tls` object in the output carries the new values:

```json
{
 "tls": {
  "certificate": null,
  "ciphers": 4,
  "minimum_version": "tls_1_2"
 },
 …
}
```

**API**

To set the minimum TLS version and the cipher suite with the API, send a `PATCH` request to the workload with the `tls` object. This body sets TLS 1.2 as the floor and suite `4`, `TLSv1.2_2021`. Keep `certificate` at the workload's current value, where `null` is the Azion SAN certificate:

```bash
curl --request PATCH \
  --url https://api.azion.com/v4/workspace/workloads/<workload-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "tls": {
    "certificate": null,
    "ciphers": 4,
    "minimum_version": "tls_1_2"
  }
}'
```

The API accepts the update, and the workload then returns the new values in `tls.ciphers` and `tls.minimum_version`. For the full request schema, refer to [Azion API](https://api.azion.com/).

A suite number outside `1` to `8` is refused. For `9`, the message is `"9" is not a valid choice.` For every field of the `tls` object, refer to [Workload settings](/en/documentation/platform/workloads/settings/#tls).

---

## Check the TLS version and the cipher of a session

Expect the new TLS settings to take several minutes to propagate across Azion's distributed infrastructure. Until then, one request can meet the old settings and the next one the new, so run the check several times until the results match.

To see the TLS version and the cipher a session negotiates, send a request with `curl` in verbose mode. The `-k` option skips the certificate check, so the command shows the handshake even when the certificate does not cover the hostname:

```bash
curl -skv https://<your-domain>/ -o /dev/null
```

In the output, the `SSL connection using` line names the TLS version and the cipher of the session. For a workload with suite `7` and `tls_1_2` as the floor, the line reads:

```text
* SSL connection using TLSv1.3 / AEAD-AES256-GCM-SHA384 / [blank] / UNDEF
```

The line shows TLS 1.3 although the floor is TLS 1.2, because the minimum version sets the lowest version the workload accepts, not the version every session uses. The cipher in that line is spelled by the client's TLS library, which can name it differently from the suite tables in [Cipher suites](/en/documentation/platform/workloads/settings/#cipher-suites).

---

## Next steps

- [Workload settings](/en/documentation/platform/workloads/settings.md#cipher-suites): Look up the ciphers each of the eight suites holds, and the TLS version of each cipher.
- [Upload a digital certificate](/en/documentation/guides/application-security/tls-and-certificates/digital-certificates.md): Serve HTTPS on your hostname with a certificate you bring.
- [Configure mTLS on a workload](/en/documentation/guides/application-security/tls-and-certificates/associate-an-mtls-certificate.md): Require a client certificate signed by a certificate authority you trust.
- [Configure HTTP and HTTPS ports](/en/documentation/guides/application-development/getting-started/configure-ports.md): Choose the ports the workload listens on for HTTP and HTTPS.
