PayPal TLS 1.2与HTTP/1.1升级警告排查求助
Let’s break down what’s likely going on here—I’ve debugged dozens of these tricky warning scenarios before, so I’ll walk through the gaps in your tests and how PayPal’s checks actually work.
1. What Might You Be Missing?
Your basic tests look solid, but these are the most common oversights that trigger false or lingering warnings:
PayPal scans your specific API/callback endpoints, not just your main site
You tested your root domain, but PayPal’s checks target the URLs you’ve set in their dashboard—think IPN webhooks, payment return pages, or API callback paths. These endpoints might have separate configurations:- The script handling callbacks could run on an older PHP version that doesn’t default to TLS 1.2 (even if your main site uses a newer version).
- A directory-specific
.htaccessor server config rule might override TLS/HTTP protocol settings.
CDN/origin server mismatch
If you use a CDN or load balancer, yourssllabsandcurltests hit the CDN’s edge nodes—but PayPal might connect directly to your origin server. Double-check that your origin server’s TLS stack also supports TLS 1.2 and HTTP/1.1 (some CDNs handle TLS termination but don’t pass the correct protocol to the origin).TLS test direction matters
Running PayPal’s PHP script on your server tests your server connecting to PayPal (outbound TLS 1.2). But PayPal’s warning is about PayPal connecting to your server (inbound TLS 1.2). Your firewall, security group, or reverse proxy might block PayPal’s IP ranges, or have inbound TLS settings that don’t prioritize TLS 1.2.Cipher suite compatibility
SSL Labs shows you support TLS 1.2, but PayPal requires modern cipher suites like AES-GCM or ChaCha20-Poly1305. If your server only offers older CBC-mode ciphers, PayPal’s scan might fail even though TLS 1.2 is enabled.Warning latency
PayPal’s scans run on a schedule—if you recently fixed your configuration, it could take 2-3 days for their system to re-scan and clear the warning.
2. How PayPal Determines If You Need an Upgrade
PayPal’s checks are tied to their upcoming API compatibility requirements:
For TLS 1.2:
- They initiate a TLS handshake with your configured endpoints using only TLS 1.2. If the handshake fails (e.g., your server rejects TLS 1.2, or uses incompatible ciphers), you get the warning.
- Even if you support TLS 1.2 alongside older versions, they may flag you if your server doesn’t prefer TLS 1.2 (i.e., it negotiates down to TLS 1.0/1.1 when requested).
For HTTP/1.1:
- They verify your server responds correctly to HTTP/1.1 requests and rejects HTTP/1.0 requests (PayPal is phasing out support for HTTP/1.0).
- They also check that your API endpoints return HTTP/1.1 responses (not HTTP/1.0) when processing their requests.
内容的提问来源于stack exchange,提问作者Craig

