Understand the TLS version and cipher suite requirements for connecting to PayNearMe APIs, including supported configurations for TLS 1.2 and 1.3 and client library recommendations to ensure secure, compliant integrations.
Security CheckupFor a step-by-step guide on how to check your site's TLS version and cipher suites, see Reviewing Your TLS Version and Cipher Suites.
To ensure secure communication and protect data in transit, all clients connecting to our APIs must meet the following Transport Layer Security (TLS) requirements,
Minimum TLS Version
- TLS 1.2 or higher is required
- TLS 1.0 and 1.1 are not supported
Deprecated Cipher Suites
Connections using the following will be rejected:
- SSL/TLS protocols below TLS 1.2
- Cipher suites using:
- RSA key exchange without PFS
- SHA-1 or MD5 hashes
- Block ciphers without AEAD (e.g., CBC without GCM)
Supported Cipher Suites
TLS 1.3
TLS 1.3 cipher suites are defined by the protocol and are AEAD-only. Key exchange and authentication are negotiated separately from the cipher suite, so suite names do not specify ECDHE, RSA, or ECDSA.
| RFC Cipher Name | openssl Cipher Name |
|---|---|
TLS_AES_128_GCM_SHA256 | TLS_AES_128_GCM_SHA256 |
TLS_AES_256_GCM_SHA384 | TLS_AES_256_GCM_SHA384 |
TLS_CHACHA20_POLY1305_SHA256 | TLS_CHACHA20_POLY1305_SHA256 |
Naming ConventionsOpenSSL 1.1.1 and later report TLS 1.3 suites using the RFC names shown above. Older releases may use the TLS13- prefixed form, for example
TLS13-AES-256-GCM-SHA384.
TLS 1.2
All supported TLS 1.2 cipher suites use ECDHE key exchange for forward secrecy with an AEAD cipher.
| RFC Cipher Name | openssl Cipher Name |
|---|---|
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 | ECDHE-RSA-AES128-GCM-SHA256 |
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 | ECDHE-ECDSA-AES128-GCM-SHA256 |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 | ECDHE-RSA-AES256-GCM-SHA384 |
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 | ECDHE-ECDSA-AES256-GCM-SHA384 |
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 | ECDHE-RSA-CHACHA20-POLY1305 |
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 | ECDHE-ECDSA-CHACHA20-POLY1305 |
Unsupported Protocols and Cipher Suites
Connections using any of the following will be rejected with a TLS handshake failure:
- TLS protocol versions below TLS 1.2, including SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1
- Cipher suites using RSA key exchange without forward secrecy
- Cipher suites using SHA-1 or MD5 hashes
- Block ciphers without AEAD, including all CBC-mode cipher suites
- 3DES cipher suites
Commonly encountered examples:
| RFC Cipher Name | openssl Cipher Name |
|---|---|
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 | ECDHE-RSA-AES128-SHA256 |
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 | ECDHE-ECDSA-AES128-SHA256 |
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA | ECDHE-RSA-AES128-SHA |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA | ECDHE-RSA-AES256-SHA |
TLS_RSA_WITH_AES_128_GCM_SHA256 | AES128-GCM-SHA256 |
TLS_RSA_WITH_AES_128_CBC_SHA | AES128-SHA |
TLS_RSA_WITH_AES_256_CBC_SHA | AES256-SHA |
TLS_RSA_WITH_3DES_EDE_CBC_SHA | DES-CBC3-SHA |
Client Configuration Requirements
- Support TLS 1.2 or higher with ECDHE key exchange and an AES-GCM or ChaCha20-Poly1305 cipher suite.
- Keep client libraries current (OpenSSL, Java, .NET, curl, and similar). OpenSSL 1.0.1 or later, Java 8 or later, and current .NET, Go, Python, and Node.js runtimes meet these requirements by default.
- Do not hardcode specific cipher suites or TLS versions. Allow your TLS library to negotiate the strongest mutually supported option.
For full compatibility details, refer to Fastly’s TLS configuration guide.
