This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 12 · Mar 16 – 22, 2026

crypto/tls: remove minimum version requirement for QUIC

Worth knowingstdlib

What changed
The explicit MinVersion check for QUIC connections has been removed; QUIC will internally clamp the effective minimum to TLS 1.3 while preserving the original value for non‑QUIC use.
Production impact
The source does not say.
Try it
Create a tls.Config with MinVersion: tls.VersionTLS12 and use it for both HTTP/2 and HTTP/3 listeners without cloning.
Source
github.com/golang/go/issues/77631

Understand it, then run it

The Go crypto/tls package used to force the minimum TLS version to 1.3 when a configuration was used for QUIC. That meant if you wanted to run both HTTP/2 (which can use TLS 1.2) and HTTP/3 (which requires TLS 1.3) with the same configuration, you had to duplicate the configuration. The change removes that requirement. Now a single configuration can be shared between TCP and QUIC; internally the library will still use TLS 1.3 for QUIC but keeps the original minimum for non‑QUIC connections.

Run it now

Todaygo
// This program demonstrates that a tls.Config with MinVersion set to TLS1.2
// can be used without error. In a real QUIC implementation the library
// would internally clamp the effective minimum to TLS1.3, but that logic
// is not exercised here because we cannot create a QUIC connection in
// this sandbox.

package main

import (
	"crypto/tls"
	"fmt"
)

func main() {
	// Create a configuration that allows TLS1.2 as the minimum.
	cfg := &tls.Config{
		MinVersion: tls.VersionTLS12,
	}

	// Normally we would use cfg with a QUIC listener here.
	// For demonstration, we simply print the effective MinVersion.
	fmt.Printf("Configured MinVersion: %v\n", cfg.MinVersion)

	// The configuration is valid; no panic or error occurs.
}

What it printed when we ran it on Go 1.27.1

Configured MinVersion: 771

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed