You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PayPal TLS 1.2与HTTP/1.1升级警告排查求助

Troubleshooting Persistent PayPal TLS 1.2 & HTTP/1.1 Upgrade Warnings

Let’s break down what’s likely going on here—I’ve debugged dozens of these tricky warning scenarios before, so I’ll walk through the gaps in your tests and how PayPal’s checks actually work.

1. What Might You Be Missing?

Your basic tests look solid, but these are the most common oversights that trigger false or lingering warnings:

  • PayPal scans your specific API/callback endpoints, not just your main site
    You tested your root domain, but PayPal’s checks target the URLs you’ve set in their dashboard—think IPN webhooks, payment return pages, or API callback paths. These endpoints might have separate configurations:

    • The script handling callbacks could run on an older PHP version that doesn’t default to TLS 1.2 (even if your main site uses a newer version).
    • A directory-specific .htaccess or server config rule might override TLS/HTTP protocol settings.
  • CDN/origin server mismatch
    If you use a CDN or load balancer, your ssllabs and curl tests hit the CDN’s edge nodes—but PayPal might connect directly to your origin server. Double-check that your origin server’s TLS stack also supports TLS 1.2 and HTTP/1.1 (some CDNs handle TLS termination but don’t pass the correct protocol to the origin).

  • TLS test direction matters
    Running PayPal’s PHP script on your server tests your server connecting to PayPal (outbound TLS 1.2). But PayPal’s warning is about PayPal connecting to your server (inbound TLS 1.2). Your firewall, security group, or reverse proxy might block PayPal’s IP ranges, or have inbound TLS settings that don’t prioritize TLS 1.2.

  • Cipher suite compatibility
    SSL Labs shows you support TLS 1.2, but PayPal requires modern cipher suites like AES-GCM or ChaCha20-Poly1305. If your server only offers older CBC-mode ciphers, PayPal’s scan might fail even though TLS 1.2 is enabled.

  • Warning latency
    PayPal’s scans run on a schedule—if you recently fixed your configuration, it could take 2-3 days for their system to re-scan and clear the warning.

2. How PayPal Determines If You Need an Upgrade

PayPal’s checks are tied to their upcoming API compatibility requirements:

For TLS 1.2:

  • They initiate a TLS handshake with your configured endpoints using only TLS 1.2. If the handshake fails (e.g., your server rejects TLS 1.2, or uses incompatible ciphers), you get the warning.
  • Even if you support TLS 1.2 alongside older versions, they may flag you if your server doesn’t prefer TLS 1.2 (i.e., it negotiates down to TLS 1.0/1.1 when requested).

For HTTP/1.1:

  • They verify your server responds correctly to HTTP/1.1 requests and rejects HTTP/1.0 requests (PayPal is phasing out support for HTTP/1.0).
  • They also check that your API endpoints return HTTP/1.1 responses (not HTTP/1.0) when processing their requests.

内容的提问来源于stack exchange,提问作者Craig

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:49:37