Hacker News new | ask | show | jobs
by toast0 990 days ago
Technically the certificate issues are separate from the protocol versioning. It's just that clients that don't support TLS 1.2 often also don't support sha2 certificates or may not have a path to validate certificates from currently available CAs (although you can usually push through that; no protocol support and no cert signature support is not a user bypass prompt)

As a side note, barely anything supports TLS 1.1 but not TLS 1.2