How To Enable TLS 1.1 & TLS 1.2 In Windows 7 and 8 (2024)

Last modified: April 3, 2022

TLS version 1.0 is not safe anymore and should be disabled. To justify, let’s just name thethreebiggest attacks that managed to exploit the various TLS 1.0 vulnerabilities discovered within 2011 and 2014:BEAST,HeartbleedandPOODLE.

This issue doesn’t affect Windows 10 users. But, always install the OS updates through the official channels. However, if you’re still using Windows 7 or Windows 8, you might have to perform some manual tasks in order to get rid of that outdated TLS version.

We can fix this by telling your OS to never use TLS 1.0 anymore, and stick with TLS 1.1 and 1.2 by default. Here’s a small guide explaining how you can do that.

Install the KB3140245 Security Patch

The first thing to do is to download and install the Windows KB3140245.
You can do that using Windows Update, since it’s available as an optional update, or manually download it from the official website (here). Mind the appropriate product version for your OS.

This will equip your OS with TLS versions 1.1 and 1.2.

Update your Windows Registry file to TLS 1.2

You need to patch your Windows Registry file, so that your OS will actually use the new TLS protocol versions (1.2, and 1.1 as a fallback) instead of the outdated and vulnerable 1.0 one.
Microsoft-released patch file was revoked. As a result, this can no longer be done automatically. You need to do it manually by editing the registry file usingregedit.

Before proceeding further, we advise you to backup your Registry.

Step 1. Setting the default TLS protocols to TLS 1.1 and 1.2

To begin, press WinKey+R, type regedit and then press enter.

After that, navigate to:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp

and add New (Edit-New or right-click on WinHttp) DWORD value and name it: DefaultSecureProtocols

How To Enable TLS 1.1 & TLS 1.2 In Windows 7 and 8 (1)

Afterwards, double-click on it and enter this hexadecimal value: 00000A00

Do the same procedure for:

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp

Subsequently, you should end up with entries as shown in the picture below:

How To Enable TLS 1.1 & TLS 1.2 In Windows 7 and 8 (2)

You have now configured your system to use TLS 1.1 and 1.2. The problematic TLS 1.0 is now disabled.

In order to re-enable TLS 1.0, use the value 00000A80 for DefaultSecureProtocols entries.

(This is not recommended. However, some sites might still require it)

Step 2. Enable TLS 1.1 and 1.2 at the SChannel component level

Firstly, we need to create subkey called Client in each of the following two keys:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\

Secondly, navigate to appropriate key and create a subkey (Edit-New-Key) called Client

Now we will have keys as shown below and in them we will add another DWORD key called DisabledByDefault

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client

Lastly, set the key value to: 0

You should now have the entries as per image below:

How To Enable TLS 1.1 & TLS 1.2 In Windows 7 and 8 (3)

Visitthis official Microsoft page in order to learn more about the entire topic.

Find other security suggestions on our Blog page.

Conclusion

Windows 10 users don’t require this fix. Disabling TLS 1.0 will patch security vulnerabilities in Windows 7 and Windows 8. We don’t advise re-enabling TLS 1.0.

If you have any other concerns that need addressing, contact our Support team directly.

How To Enable TLS 1.1 & TLS 1.2 In Windows 7 and 8 (2024)
Top Articles
Pricing your listing - Airbnb Help Center
The Top Ten Warning Signs You Are Talking to a Catfisher
Chs.mywork
Jazmen Jafar Linkedin
Eric Rohan Justin Obituary
877-668-5260 | 18776685260 - Robocaller Warning!
Fnv Turbo
Farmers Branch Isd Calendar
Poplar | Genus, Description, Major Species, & Facts
Gw2 Legendary Amulet
Craigslist Dog Sitter
Atrium Shift Select
Vocabulario A Level 2 Pp 36 40 Answers Key
State Of Illinois Comptroller Salary Database
Housework 2 Jab
Nene25 Sports
Dutch Bros San Angelo Tx
Parent Resources - Padua Franciscan High School
Kaitlyn Katsaros Forum
Rochester Ny Missed Connections
2021 Volleyball Roster
Rogue Lineage Uber Titles
Everything To Know About N Scale Model Trains - My Hobby Models
Marilyn Seipt Obituary
The Collective - Upscale Downtown Milwaukee Hair Salon
Unity Webgl Car Tag
Criglist Miami
Imagetrend Elite Delaware
Craigslist Sf Garage Sales
L'alternativa - co*cktail Bar On The Pier
October 19 Sunset
Walter King Tut Johnson Sentenced
Navigating change - the workplace of tomorrow - key takeaways
Roto-Rooter Plumbing and Drain Service hiring General Manager in Cincinnati Metropolitan Area | LinkedIn
Federal Student Aid
The Land Book 9 Release Date 2023
Zero Sievert Coop
My.lifeway.come/Redeem
Brandon Spikes Career Earnings
Sams Gas Price Sanford Fl
Tattoo Shops In Ocean City Nj
22 Golden Rules for Fitness Beginners – Barnes Corner Fitness
Amy Zais Obituary
Tropical Smoothie Address
Jackerman Mothers Warmth Part 3
Germany’s intensely private and immensely wealthy Reimann family
Deshuesadero El Pulpo
Texas Lottery Daily 4 Winning Numbers
Wayward Carbuncle Location
Latest Posts
Article information

Author: Dong Thiel

Last Updated:

Views: 5659

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Dong Thiel

Birthday: 2001-07-14

Address: 2865 Kasha Unions, West Corrinne, AK 05708-1071

Phone: +3512198379449

Job: Design Planner

Hobby: Graffiti, Foreign language learning, Gambling, Metalworking, Rowing, Sculling, Sewing

Introduction: My name is Dong Thiel, I am a brainy, happy, tasty, lively, splendid, talented, cooperative person who loves writing and wants to share my knowledge and understanding with you.