megachangelog
Announcement2026.10.07

X25519-only TLS ends for GitHub Enterprise Cloud on October 7

GitHub Enterprise Cloud with data residency will no longer accept TLS connections from clients that offer only X25519 for key agreement starting October 7, 2026. Customers should ensure their clients support additional key agreement algorithms.

Beginning October 7, 2026, GitHub Enterprise Cloud with data residency will no longer accept TLS connections from clients that offer only X25519 for key agreement.

Most customers don’t need to take action. The affected endpoints will continue to support the FIPS-approved P-256 (secp256r1) and P-384 (secp384r1) groups. Current browsers, operating systems, GitHub CLI releases, and commonly used TLS libraries already support P-256.

You may be affected if an application, proxy, security appliance, or TLS library is explicitly configured to offer only X25519. Before October 7, 2026, you should:

  • Update your operating system, runtime, GitHub CLI, proxy, and TLS libraries to supported versions.
  • Remove any X25519-only configuration.
  • Ensure P-256 (secp256r1) is enabled. You may also enable P-384 (secp384r1).

After October 7, X25519-only clients will be unable to establish HTTPS connections. This change applies only to GitHub Enterprise Cloud with data residency. SSH connectivity is not affected.

If you need help validating your TLS configuration, contact GitHub Support.

The post X25519-only TLS ends for GHE.com on October 7 appeared first on The GitHub Blog.

tlssecurityghebreakingmigration

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →