# How to enable specific TLS version on transport port

**URL:** https://forum.search-guard.com/t/how-to-enable-specific-tls-version-on-transport-port/703
**Category:** Search Guard
**Created:** [December 7, 2017, 2:09am UTC](https://forum.search-guard.com/t/how-to-enable-specific-tls-version-on-transport-port/703 "2017-12-07T02:09:43Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![askids](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@askids](https://forum.search-guard.com/u/askids)
#### Post date: [December 7, 2017, 2:09am UTC](https://forum.search-guard.com/t/how-to-enable-specific-tls-version-on-transport-port/703/1 "2017-12-07T02:09:43Z")

</div>

Hi,

For http, I see that there is a configuration to enable specific version of TLS protocol. However at least in documentation, equivalent property is not available for transport layer. So if we want to enforce let's say TLS v1.2 for transport layer, how do we achieve that? If this is not an option, then what is the default that Searchguard SSL will use?

Thanks!

---

<div class="post-metadata">

### Author: ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)
#### Post date: [December 8, 2017, 5:33pm UTC](https://forum.search-guard.com/t/how-to-enable-specific-tls-version-on-transport-port/703/2 "2017-12-08T17:33:43Z")

</div>

# Enabled SSL cipher suites for transport protocol (only Java format is supported)  
# WARNING: Expert setting, do only use if you know what you are doing  
# If you set wrong values here this this could be a security risk  
#searchguard.ssl.transport.enabled\_ciphers:  
# - "TLS\_DHE\_RSA\_WITH\_AES\_256\_CBC\_SHA"  
# - "TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256"  
&nbsp;&nbsp;  
# Enabled SSL protocols for transport protocol (only Java format is supported)  
# WARNING: Expert setting, do only use if you know what you are doing  
# If you set wrong values here this this could be a security risk  
#searchguard.ssl.transport.enabled\_protocols:  
# - "TLSv1.2"

[https://github.com/floragunncom/search-guard-ssl/blob/5.6.0/searchguard-ssl-config-template.yml](https://github.com/floragunncom/search-guard-ssl/blob/5.6.0/searchguard-ssl-config-template.yml)

> **···**
>
> > Am 07.12.2017 um 03:09 schrieb askids \<ashokds@gmail.com\>:
> > 
> > Hi,
> > 
> > For http, I see that there is a configuration to enable specific version of TLS protocol. However at least in documentation, equivalent property is not available for transport layer. So if we want to enforce let's say TLS v1.2 for transport layer, how do we achieve that? If this is not an option, then what is the default that Searchguard SSL will use?
> > 
> > Thanks!
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/5f9f9986-5013-4c65-aace-defcbd454b28%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/5f9f9986-5013-4c65-aace-defcbd454b28%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

### Author: ![askids](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@askids](https://forum.search-guard.com/u/askids)
#### Post date: [December 19, 2017, 1:41am UTC](https://forum.search-guard.com/t/how-to-enable-specific-tls-version-on-transport-port/703/3 "2017-12-19T01:41:21Z")

</div>

Thank you. I will try this.

> **···**
>
> On Friday, December 8, 2017 at 12:33:46 PM UTC-5, Search Guard wrote:
> 
> > # Enabled SSL cipher suites for transport protocol (only Java format is supported)
> > 
> > # WARNING: Expert setting, do only use if you know what you are doing
> > 
> > # If you set wrong values here this this could be a security risk
> > 
> > #searchguard.ssl.transport.enabled\_ciphers:
> > 
> > # - “TLS\_DHE\_RSA\_WITH\_AES\_256\_CBC\_SHA”
> > 
> > # - “TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256”
> > 
> > # Enabled SSL protocols for transport protocol (only Java format is supported)
> > 
> > # WARNING: Expert setting, do only use if you know what you are doing
> > 
> > # If you set wrong values here this this could be a security risk
> > 
> > #searchguard.ssl.transport.enabled\_protocols:
> > 
> > # - “TLSv1.2”
> > 
> > [https://github.com/floragunncom/search-guard-ssl/blob/5.6.0/searchguard-ssl-config-template.yml](https://github.com/floragunncom/search-guard-ssl/blob/5.6.0/searchguard-ssl-config-template.yml)
> > 
> > > Am 07.12.2017 um 03:09 schrieb askids [ash...@gmail.com](mailto:ash...@gmail.com):
> > 
> > > Hi,
> > 
> > > For http, I see that there is a configuration to enable specific version of TLS protocol. However at least in documentation, equivalent property is not available for transport layer. So if we want to enforce let’s say TLS v1.2 for transport layer, how do we achieve that? If this is not an option, then what is the default that Searchguard SSL will use?
> > 
> > > Thanks!
> > 
> > > –  
> > > You received this message because you are subscribed to the Google Groups “Search Guard Community Forum” group.
> > 
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > 
> > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > 
> > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/5f9f9986-5013-4c65-aace-defcbd454b28%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/5f9f9986-5013-4c65-aace-defcbd454b28%40googlegroups.com).
> > 
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
