MCPP-TRN02: Legacy TLS (1.0/1.1) accepted¶
| Family | Transport |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
TLS 1.0 and 1.1 are deprecated (RFC 8996) and have known weaknesses. RFC 8414 requires TLS 1.2 for authorization servers; BCP 195 applies to protected resources (RFC 9728 ยง7.1).
Remediation¶
Set the minimum TLS version to 1.2 (prefer 1.3) on the load balancer, reverse proxy or gateway in front of the server.
References¶
- RFC 8996 Deprecating TLS 1.0 and 1.1
- RFC 9325 (BCP 195) TLS Recommendations
- RFC 8414 Authorization Server Metadata
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31