The Legacy Obituaries

TLS 1.0 / 1.1 network encryption

pre-11.2 · security · deprecated 21c · desupported 26ai

Lives on unchanged in Azure.

✓ certified by the mortician

In life

Oracle Net can protect client connections with Transport Layer Security, negotiating the protocol version between client and server. Versions 1.0 and 1.1 are the legacy protocol levels that predate the current security baseline.

Migrations care because clients, drivers and middleware that still connect to Oracle sources over the old versions have to be upgraded before or during the move; Azure services require TLS 1.2 or later, and connections to Oracle Database@Azure or between databases over links are subject to the same limits. The list of TLS versions in sqlnet.ora and client configuration is therefore part of the inventory.

Oracle's 21c Upgrade Guide deprecates TLS 1.0 and 1.1, and the 26ai guide desupports them (notice dated April 2023) in favor of TLS 1.2 and 1.3. The 26ai page also desupports the parameter that re-enabled SSLv3 and the anonymous Diffie-Hellman cipher suites.

Cause of departure

Desupported in Oracle Database 26ai after deprecation in 21c. Oracle names TLS 1.2 or TLS 1.3 as the successor.

Obituary

TLS 1.0 / 1.1 network encryption, introduced before 11.2, secured Oracle network connections through two once-serviceable protocol versions. It performed its duties until newer standards made its continued presence less reassuring than nostalgic.

Deprecated in 21c and desupported in 26ai, it yields to TLS 1.2 or TLS 1.3. Azure likewise denies or retires the older versions, leaving outdated drivers to contemplate an overdue upgrade.

It is survived by Azure Database for PostgreSQL Flexible Server, where it lives on unchanged in newer form, though mutual TLS and custom server certificates are unsupported. Azure SQL Database also carries it on unchanged, accepting TLS 1.2 and above while permitting TLS 1.3 to be required.

Survived by

Azure Database for PostgreSQL Flexible Server exact effort S

Applies to Oracle 11.2, 12.1, 12.2, 18c, 19c, 21c, 23ai, 26ai

Flexible Server requires TLS on every connection by default and accepts only TLS 1.2 and 1.3, denying 1.0 and 1.1, which matches Oracle's desupport of the older versions. It does not offer mutual TLS or custom server certificates, so wallet-based client certificate authentication used with Oracle Net cannot be reproduced and must become password or Entra authentication.

  • Keep require_secure_transport on and optionally set ssl_min_protocol_version to TLSv1.3.
  • Configure clients with sslmode=verify-full or verify-ca and the Azure root CA certificates, not pinned intermediates.
  • Replace Oracle client-certificate authentication with Entra or password authentication.

Complications

minor Azure Database for PostgreSQL Flexible Server accepts only TLS 1.2 and 1.3 and denies TLS 1.0 and 1.1 by default, enforces TLS through require_secure_transport (which can be turned off but is not recommended), and does not support mutual TLS client certificates or custom server certificates.

Azure SQL Database exact effort S

Applies to Oracle 11.2, 12.1, 12.2, 18c, 19c, 21c, 23ai, 26ai

Azure SQL Database and Managed Instance already enforce what Oracle's desupport of TLS 1.0 and 1.1 demands: those versions are retired, the lowest configurable minimum is TLS 1.2, the default accepts TLS 1.2 and above, and TLS 1.3 can be required. The migration task is on the client side, upgrading drivers that cannot negotiate TLS 1.2 or later.

  • Audit client TLS versions with SQL auditing (client_tls_version_name) or the portal connection metrics.
  • Upgrade drivers and runtimes that cannot negotiate TLS 1.2.
  • Set the server minimum TLS version to 1.2 (or 1.3 after driver testing).

Complications

minor For Azure SQL Database TLS 1.0 and 1.1 are retired and no longer available, the lowest configurable minimum TLS version is 1.2, the default accepts TLS 1.2 and above, enforcing a minimum of 1.3 may break drivers that lack TLS 1.3 support, and since November 2024 the minimum for SQL Database and Managed Instance cannot be set below 1.2.

Notices of correction

  1. oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 21c) · Upgrade Guide 21c, F17069-48, Feb 2026 · read 2026-09-26
  2. oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 26ai) · Upgrade Guide 26ai, G43570-12, updated Jul 2026 · read 2026-09-26
  3. microsoft Transport Layer Security in Azure Database for PostgreSQL Flexible Server · page updated 2026-07-16 · read 2026-09-26
  4. microsoft Connectivity settings for Azure SQL Database (minimum TLS version) · page updated 2026-07-28 · read 2026-09-26

← All notices

TLS 1.0 / 1.1 network encryption — Legacy Obituaries