Unspecified Minimum TLS Version in Properties.

Taimur Zahid 21 Reputation points
2023-01-03T07:31:00.877+00:00

Min TLS Version in the Properties of the IoT Hub Setting "specifies the minimum TLS version to support for this hub. Can be set to "1.2" to have clients that use a TLS version below 1.2 to be rejected."

What are the consequences for not specifying it?

Azure IoT Hub
Azure IoT Hub
An Azure service that enables bidirectional communication between internet of things (IoT) devices and applications.
0 comments No comments
{count} votes

Answer accepted by question author
  1. AshokPeddakotla-MSFT 36,006 Reputation points Moderator
    2023-01-03T08:54:25.853+00:00

    @Taimur Zahid Welcome to Microsoft Q&A forum! Thanks for your query.

    I believe you are referring to the below section.

    275622-image.png

    What are the consequences for not specifying it?

    If the minimum TLS version is not specified in Azure IoT Hub, it could potentially lead to security vulnerabilities. The minimum TLS version specifies the minimum level of encryption that is required for communication between devices and the IoT Hub. By not specifying a minimum TLS version, there is a risk that devices could connect using weaker encryption standards, which could potentially be exploited by hackers. This could lead to sensitive data being compromised, and could also potentially allow unauthorized access to the IoT system. It is important to specify a minimum TLS version to ensure that communication between devices and the IoT Hub is secure.

    IoT Hub uses Transport Layer Security (TLS) to secure connections from IoT devices and services. Three versions of the TLS protocol are currently supported, namely versions 1.0, 1.1, and 1.2.

    TLS 1.0 and 1.1 are considered legacy and are planned for deprecation. see Deprecating TLS 1.0 and 1.1 for IoT Hub. To avoid future issues, use TLS 1.2 as the only TLS version when connecting to IoT Hub.

    IoT Hub will continue to support TLS 1.0/1.1 until further notice. However, we recommend that all customers migrate to TLS 1.2 as soon as possible.

    This blog post : Azure IoT TLS: Critical changes are almost here! (…and why you should care) contains important information about TLS certificate changes for Azure IoT Hub and DPS endpoints that will impact IoT device connectivity.

    Also, see Transport Layer Security (TLS) support in IoT Hub for more details.

    Hope this clarifies your query. Do let us know if you have any further queries.

    If the response is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Matthijs van der Veer 4,376 Reputation points MVP Volunteer Moderator
    2023-01-03T08:36:45.53+00:00

    Not specifying it has very little consequence, TLS 1.0 and 1.1 are being deprecated. Setting the TLS version is only possible in a few regions (full list here). In those regions, you can enforce TLS 1.2 and reject older versions. If you don't specify it, IoT Hub will accept connections from older TLS versions, until they are deprecated. Microsoft has not documented the timeline for this.

    You can read more about the deprecation here.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.