Deprecation of Legacy TLS 1.0 and 1.1 Versions
webkit.org
webkit.org
If you want Nginx to use TLS v1.2, this is what you need:
ssl_protocols TLSv1.2;
…and if you compile a recent Nginx from source and bake in OpenSSL 1.1.1 while you do that, you can have TLS v1.3 with a TLS v1.2 fallback, too: ssl_protocols TLSv1.3 TLSv1.2;
See also:Programs like web servers that expose a list here are doing that because the libraries they use did that, not because it makes any sense to configure it this way.
Of course the real fix is to change libraries to offer an appropriate API but handling the distance between what a pre-existing library does out off the box and what users want/need is the whole point of application software.
Later TLS 1.4 comes out. How can I allow new TLS 1.4 and existing TLS 1.2 clients without allowing TLS 1.3 clients using your method.
The server software would have to be updated to include a blacklist or go back to being an ordered list.
In my opinion, the `ssl_protocols` config should accept a string like "TLSv1.2+ -TLSv1.3", basically stating a minimum version, allowing exclusions and including anything newer. In the same spirit, one should be able to do "TLSv1.0-TLSv1.2" for setting a maximum, with specific exclusions if a new TLS version ever becomes a problem.
EDIT: Here is a description of protocol selection: https://en.wikipedia.org/wiki/Transport_Layer_Security#Basic... and shows the basic negotiation phase.
(first two bullet points under the first numbered item)
Default: ssl_protocols TLSv1 TLSv1.1 TLSv1.2;