X25519-only TLS ends for GHE.com on October 7

Beginning October 7, 2026, GitHub Enterprise Cloud with data residency will no longer accept TLS connections from clients that offer only X25519 for key agreement.

Most customers don’t need to take action. The affected endpoints will continue to support the FIPS-approved P-256 (secp256r1) and P-384 (secp384r1) groups. Current browsers, operating systems, GitHub CLI releases, and commonly used TLS libraries already support P-256.

You may be affected if an application, proxy, security appliance, or TLS library is explicitly configured to offer only X25519. Before October 7, 2026, you should:

  • Update your operating system, runtime, GitHub CLI, proxy, and TLS libraries to supported versions.
  • Remove any X25519-only configuration.
  • Ensure P-256 (secp256r1) is enabled. You may also enable P-384 (secp384r1).

After October 7, X25519-only clients will be unable to establish HTTPS connections. This change applies only to GitHub Enterprise Cloud with data residency. SSH connectivity is not affected.

If you need help validating your TLS configuration, contact GitHub Support.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论