TLS 1.3 is the latest version of the security protocol your website uses for an encrypted HTTPS connection. Compared to TLS 1.2, it is faster, more secure, and easier to configure because outdated and vulnerable encryption methods have been removed. In this article, you’ll learn exactly what TLS 1.3 changes, what benefits it offers, and how to enable it step by step.
What is TLS 1.3?
TLS stands for Transport Layer Security and is the protocol that provides an encrypted connection between the visitor and the server, recognizable by the padlock in the browser. TLS 1.3 is the successor to TLS 1.2 and is designed to make the handshake, the moment when the browser and server agree on how to encrypt, shorter and more secure. Old and weak cipher suites have been removed, leaving fewer choices that can go wrong.
Benefits compared to TLS 1.2
The most important improvements of TLS 1.3 are noticeable in speed and security:
- Faster handshake: whereas TLS 1.2 requires multiple round-trip messages to establish a connection, TLS 1.3 does this in fewer steps, which shortens your page’s loading time.
- Fewer vulnerable cipher suites: outdated encryption methods such as RC4 and older SHA-1 variants have been removed, making known attacks no longer possible.
- Forward secrecy by default: each session gets a unique key, so compromising one key doesn’t mean previous communication can still be decrypted.
- Simpler configuration: with fewer options, the chance of an incorrect or insecure setting is smaller.
These improvements also count toward security checks such as those from internet.nl, where a modern TLS configuration directly contributes to a higher score.
Enabling TLS 1.3 in Plesk
On a server with Plesk and LiteSpeed, TLS 1.3 is usually already available, but it’s good to check whether the protocol is actually active for your domain.
Log in to Plesk
Go to your Plesk panel and open the domain for which you want to check TLS.
Open SSL/TLS Certificates
Go to the SSL/TLS Certificates section and check whether a valid certificate is linked to the domain.
Check the server settings
Go to Tools & Settings and then to the server’s SSL/TLS settings to see which protocols are allowed.
Disable outdated protocols
Turn off TLS 1.0 and TLS 1.1 so visitors automatically connect via TLS 1.2 or TLS 1.3.
Restart the web server
Apply the changes and restart the web service so the new settings become active.
If you don’t have access to these server settings yourself, our support team will gladly arrange this for you via a ticket or WhatsApp.
Checking whether TLS 1.3 is active
After configuring it, you’ll naturally want to make sure everything is correct. Open your website in a modern browser and check via the developer tools (Security tab) which TLS version is used when loading the page. You can also use an external SSL test to get a full report on your certificate and protocol configuration.
Also pay attention to your email configuration: a correctly configured business email environment also benefits from modern TLS settings when sending and receiving messages. If you’re unsure whether your current provider has set this up correctly, you’ll find more background articles about server security in our knowledge base.
Frequently Asked Questions
Does TLS 1.3 work on all browsers?
All recent versions of major browsers support TLS 1.3. If a visitor is still using a very outdated browser, the connection automatically falls back to TLS 1.2.
Do I need to disable TLS 1.2 entirely?
That is not required. You can keep TLS 1.2 active alongside TLS 1.3 for compatibility, as long as outdated versions like TLS 1.0 and 1.1 are disabled.
Does TLS 1.3 affect my domain name or DNS?
No, TLS 1.3 has no effect on your domain names or DNS settings. It purely concerns the encryption of traffic to your server.
Can I use TLS 1.3 with any hosting provider?
This depends on your provider’s server software. If your site runs on an outdated server stack, TLS 1.3 may not be available.
Conclusion
TLS 1.3 makes your website faster and more secure thanks to a shorter handshake and the removal of outdated encryption methods. On a modern server with Plesk, you can easily enable it via the SSL/TLS settings. Want to be sure your hosting has this properly configured by default? Check out our web hosting or read how easy it is to switch to Tandata.