Set the TLS cipher suite
Set the minimum TLS version and the cipher suite a workload accepts over HTTPS, from Azion Console, the Azion CLI, or the API.
You can set the lowest TLS version and the cipher suite that a workload accepts over HTTPS from Azion Console, the Azion CLI, or the API. To choose the certificate the workload presents instead, refer to Upload a digital certificate.
A cipher suite is a named set of ciphers. During the TLS handshake, the client and the workload negotiate one cipher from the suite for the session. The minimum TLS version is a floor: a client that supports only older versions cannot connect.
An account that runs on API v3 sets the minimum TLS version and the cipher suite in the Main Settings of each application instead. For more information, refer to Main Settings.
Choose the interface you work in. The prerequisites and every procedure below switch to it.
Prerequisites
- A workload whose deployment names an application. To create a workload and its deployment, refer to Workloads quickstart.
- A hostname that reaches the workload over HTTPS, such as its workload domain, to check the result.
- Access to Azion Console. For more information, refer to How to access Azion Console.
Set the minimum TLS version and the cipher suite
A new workload accepts TLS 1.3 at the lowest, tls_1_3, and offers suite 7, Modern_v2025Q1. The minimum version takes tls_1_0, tls_1_1, tls_1_2, or tls_1_3. TLS 1.0 and TLS 1.1 are deprecated. The suite takes a number from 1 to 8. Each number selects one named suite, and Cipher suites lists the ciphers each one holds.
To set the minimum TLS version and the cipher suite with the Azion CLI, save a JSON file with the workload ID and the tls object, here as tls.json. This file sets TLS 1.2 as the floor and suite 4, TLSv1.2_2021. Keep certificate at the value azion describe workload returns for the workload, where null is the Azion SAN certificate:
Update the workload with the file:
On success, the CLI returns the workload ID:
To confirm the change, describe the workload:
The tls object in the output carries the new values:
A suite number outside 1 to 8 is refused. For 9, the message is "9" is not a valid choice. For every field of the tls object, refer to Workload settings.
Check the TLS version and the cipher of a session
Expect the new TLS settings to take several minutes to propagate across Azion’s distributed infrastructure. Until then, one request can meet the old settings and the next one the new, so run the check several times until the results match.
To see the TLS version and the cipher a session negotiates, send a request with curl in verbose mode. The -k option skips the certificate check, so the command shows the handshake even when the certificate does not cover the hostname:
In the output, the SSL connection using line names the TLS version and the cipher of the session. For a workload with suite 7 and tls_1_2 as the floor, the line reads:
The line shows TLS 1.3 although the floor is TLS 1.2, because the minimum version sets the lowest version the workload accepts, not the version every session uses. The cipher in that line is spelled by the client’s TLS library, which can name it differently from the suite tables in Cipher suites.