GitHub Enterprise Cloud with data residency refuses X25519-only TLS clients from 7 October 2026
EditorialBy TrustList Editorial
From 7 October 2026, GHE.com (GitHub Enterprise Cloud with data residency) stops accepting HTTPS clients that offer only X25519 for key agreement. Make sure P-256 is enabled in proxies, appliances and TLS libraries. SSH is not affected.
- United States
- San Francisco, Ca
- DevOps
- Version Control
- +2 more
About GitHub Enterprise Cloud with data residency refuses X25519-only TLS clients from 7 October 2026
GitHub Enterprise Cloud with data residency refuses X25519-only TLS clients from 7 October 2026
1 October 2026 — GitHub gave customers of GitHub Enterprise Cloud with data residency, the service run on GHE.com, one week's notice of a change to how its HTTPS endpoints negotiate encryption. From 7 October 2026 they will no longer accept TLS connections from clients that offer only X25519 for key agreement. The notice was posted to the GitHub Changelog on 30 September 2026.
Not yet independently verified. This rests on GitHub’s own changelog entry; no independent report of it was found. The entry’s web address says “September 15” while its title and text say 7 October; we have used the date in the text. We will update this when it can be confirmed, and remove this note.
What changes
The affected endpoints will keep supporting the FIPS-approved P-256 (secp256r1) and P-384 (secp384r1) groups. Only a client that offers X25519 and nothing else will fail. GitHub says that after 7 October such clients "will be unable to establish HTTPS connections".
Three limits matter:
- It applies only to GitHub Enterprise Cloud with data residency (GHE.com). github.com and GitHub Enterprise Server are not mentioned.
- SSH is not affected. Git over SSH keeps working whatever your TLS settings.
- GitHub says most customers need do nothing. Current browsers, operating systems, GitHub CLI releases and common TLS libraries already support P-256.
Who could be caught out
The risk sits in the middle of the network, not on developers' laptops. GitHub names applications, proxies, security appliances and TLS libraries that have been explicitly configured to offer only X25519. In practice that means:
- TLS-inspecting proxies and secure web gateways with a hardened, X25519-only cipher profile;
- CI runners and build containers on old or hand-tuned images;
- in-house tools built on a TLS library pinned to a single curve;
- integrations and bots calling the GHE.com API from locked-down networks.
When one of these fails it will look like a network outage: clones, pushes over HTTPS, API calls and webhooks deliveries through that path stop, while SSH keeps working.
What to do before 7 October
- Check proxy and appliance TLS profiles used for GHE.com traffic. Make sure P-256 is offered; P-384 may be added too.
- Remove any X25519-only setting from client configuration, runtime flags and TLS library options.
- Update operating systems, runtimes, GitHub CLI and TLS libraries on runners and servers to supported versions.
- Test from each network path before the date, for example by forcing P-256 in a test client, and fix any path that cannot negotiate it.
- If you are unsure, GitHub asks customers to contact GitHub Support to validate their TLS configuration.
Sources
- GitHub Changelog: X25519-only TLS ends for GHE.com on October 7 — 30 September 2026
Categories & features
- United States
- San Francisco, Ca
- DevOps
- Version Control
- Source Code Management Software
- Encryption
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.