TLS 1.0 / 1.1 network encryption
Lives on unchanged in Azure.
✓ certified by the mortician
In life
Oracle Net can protect client connections with Transport Layer Security, negotiating the protocol version between client and server. Versions 1.0 and 1.1 are the legacy protocol levels that predate the current security baseline.
Migrations care because clients, drivers and middleware that still connect to Oracle sources over the old versions have to be upgraded before or during the move; Azure services require TLS 1.2 or later, and connections to Oracle Database@Azure or between databases over links are subject to the same limits. The list of TLS versions in sqlnet.ora and client configuration is therefore part of the inventory.
Oracle's 21c Upgrade Guide deprecates TLS 1.0 and 1.1, and the 26ai guide desupports them (notice dated April 2023) in favor of TLS 1.2 and 1.3. The 26ai page also desupports the parameter that re-enabled SSLv3 and the anonymous Diffie-Hellman cipher suites.
Cause of departure
Desupported in Oracle Database 26ai after deprecation in 21c. Oracle names TLS 1.2 or TLS 1.3 as the successor.
Obituary
TLS 1.0 / 1.1 network encryption, introduced before 11.2, secured Oracle network connections through two once-serviceable protocol versions. It performed its duties until newer standards made its continued presence less reassuring than nostalgic.
Deprecated in 21c and desupported in 26ai, it yields to TLS 1.2 or TLS 1.3. Azure likewise denies or retires the older versions, leaving outdated drivers to contemplate an overdue upgrade.
It is survived by Azure Database for PostgreSQL Flexible Server, where it lives on unchanged in newer form, though mutual TLS and custom server certificates are unsupported. Azure SQL Database also carries it on unchanged, accepting TLS 1.2 and above while permitting TLS 1.3 to be required.
Survived by
Azure Database for PostgreSQL Flexible Server exact effort S
Flexible Server requires TLS on every connection by default and accepts only TLS 1.2 and 1.3, denying 1.0 and 1.1, which matches Oracle's desupport of the older versions. It does not offer mutual TLS or custom server certificates, so wallet-based client certificate authentication used with Oracle Net cannot be reproduced and must become password or Entra authentication.
- Keep require_secure_transport on and optionally set ssl_min_protocol_version to TLSv1.3.
- Configure clients with sslmode=verify-full or verify-ca and the Azure root CA certificates, not pinned intermediates.
- Replace Oracle client-certificate authentication with Entra or password authentication.
Complications
Azure SQL Database exact effort S
Azure SQL Database and Managed Instance already enforce what Oracle's desupport of TLS 1.0 and 1.1 demands: those versions are retired, the lowest configurable minimum is TLS 1.2, the default accepts TLS 1.2 and above, and TLS 1.3 can be required. The migration task is on the client side, upgrading drivers that cannot negotiate TLS 1.2 or later.
- Audit client TLS versions with SQL auditing (client_tls_version_name) or the portal connection metrics.
- Upgrade drivers and runtimes that cannot negotiate TLS 1.2.
- Set the server minimum TLS version to 1.2 (or 1.3 after driver testing).
Complications
Notices of correction
- oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 21c) · Upgrade Guide 21c, F17069-48, Feb 2026 · read 2026-09-26
- oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 26ai) · Upgrade Guide 26ai, G43570-12, updated Jul 2026 · read 2026-09-26
- microsoft Transport Layer Security in Azure Database for PostgreSQL Flexible Server · page updated 2026-07-16 · read 2026-09-26
- microsoft Connectivity settings for Azure SQL Database (minimum TLS version) · page updated 2026-07-28 · read 2026-09-26