To increase security, App Engine automatically opts
your application into TLS version 1.2 and later, with supported cipher
suites, and might permanently block insecure traffic
with TLS version 1.1 and earlier. For appspot.com domains, this block occurs at the connection level. For custom domains, the connection might succeed, but the requests are blocked.
If your project is permanently blocked from using TLS version 1.1 and earlier, and you require additional time to switch to TLS 1.2 and later, contact Support.
For new applications, App Engine only allows secure traffic with TLS version 1.2 and later, with supported cipher suites, by default. If your application only requires TLS version 1.2 and later with the default supported cipher suites, you don't need to configure a global external Application Load Balancer to route requests. However, if you need to support a different set of cipher suites, or require connection-level (handshake) rejection of insecure TLS versions for custom domains, configure a global external Application Load Balancer.
Supported TLS versions and cipher suites
The security of TLS connections depends on the negotiated cipher suite, a combination of cryptographic algorithms. These cipher suites are identified by IANA values, as detailed in the following table:
| TLS version | IANA value | Cipher suite |
|---|---|---|
| TLS v1.3 | 0x1301 | TLS_AES_128_GCM_SHA256 |
| 0x1302 | TLS_AES_256_GCM_SHA384 | |
| 0x1303 | TLS_CHACHA20_POLY1305_SHA256 | |
| TLS v1.2 | 0xCCA9 | TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 |
| 0xCCA8 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 | |
| 0xC02B | TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 | |
| 0xC02F | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 | |
| 0xC02C | TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 | |
| 0xC030 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 | |
| 0xC009 | TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA | |
| 0xC013 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA | |
| 0xC00A | TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA | |
| 0xC014 | TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA |
If you need to use a different or a less restrictive cipher suite, we recommend that you use a global external Application Load Balancer. For more information, see Set up a classic Application Load Balancer with App Engine and SSL policies for SSL and TLS protocols in the Cloud Load Balancing documentation.
Update the TLS versions allowed for your app
App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For projects where older TLS versions have been permanently blocked, you can't use the following settings to update to an older TLS version. If your project requires older TLS versions, contact Support.
When you create or update your application, use the --ssl-policy flag to
specify the minimum permitted TLS version.
To set a minimum TLS version while creating your app:
gcloud app create --ssl-policy=TLS_VERSION
To set a minimum TLS version while updating your app:
gcloud app update --ssl-policy=TLS_VERSION
Replace TLS_VERSION with TLS_VERSION_1_2. This only allows TLS version
1.2 and later, with modern cipher suites.
Disable custom TLS versions and ciphers
If you use Cloud Load Balancing and serverless NEGS to route traffic to your App Engine application, you can further restrict TLS versions or ciphers by defining an SSL security policy on your load balancer.
What's next
To verify and manage SSL certificates, see Secure custom domains with SSL.
To enable Cloud Load Balancing to manage incoming requests to your custom domain, see Migrate App Engine custom domain to Cloud Load Balancing.