Deprecate TLS v1.2 for PCI-DSS v3.2.1 Requirement 2.2.3
Open
@cmlh is already working on this.
Since May 2, 2021.
- Dominant language
- HTML
- Stars
- 3.6k
- Forks
- 831
- Avg merge
- 7h 55m
- Merged PRs (30d)
- 4
Description
I would like to propose that OWASP recommend the migration from TLS v1.2 to TLS v1.3 [or later] to support PCI-DSS v3.2.1 Requirement 2.2.3 reproduced below:

Therefore, V9.1 Client Communications Security will need to be modified.
The alignment with PCI-DSS v3.2.1 is tracked by GitHub Issue https://github.com/OWASP/ASVS/issues/317#issuecomment-829077114
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.