Skip to content
TrustList
News

GitHub Enterprise Cloud with data residency refuses X25519-only TLS clients from 7 October 2026

Editorial

By TrustList Editorial

From 7 October 2026, GHE.com (GitHub Enterprise Cloud with data residency) stops accepting HTTPS clients that offer only X25519 for key agreement. Make sure P-256 is enabled in proxies, appliances and TLS libraries. SSH is not affected.

About GitHub Enterprise Cloud with data residency refuses X25519-only TLS clients from 7 October 2026

GitHub Enterprise Cloud with data residency refuses X25519-only TLS clients from 7 October 2026

1 October 2026 — GitHub gave customers of GitHub Enterprise Cloud with data residency, the service run on GHE.com, one week's notice of a change to how its HTTPS endpoints negotiate encryption. From 7 October 2026 they will no longer accept TLS connections from clients that offer only X25519 for key agreement. The notice was posted to the GitHub Changelog on 30 September 2026.

Not yet independently verified. This rests on GitHub’s own changelog entry; no independent report of it was found. The entry’s web address says “September 15” while its title and text say 7 October; we have used the date in the text. We will update this when it can be confirmed, and remove this note.

What changes

The affected endpoints will keep supporting the FIPS-approved P-256 (secp256r1) and P-384 (secp384r1) groups. Only a client that offers X25519 and nothing else will fail. GitHub says that after 7 October such clients "will be unable to establish HTTPS connections".

Three limits matter:

  • It applies only to GitHub Enterprise Cloud with data residency (GHE.com). github.com and GitHub Enterprise Server are not mentioned.
  • SSH is not affected. Git over SSH keeps working whatever your TLS settings.
  • GitHub says most customers need do nothing. Current browsers, operating systems, GitHub CLI releases and common TLS libraries already support P-256.

Who could be caught out

The risk sits in the middle of the network, not on developers' laptops. GitHub names applications, proxies, security appliances and TLS libraries that have been explicitly configured to offer only X25519. In practice that means:

  • TLS-inspecting proxies and secure web gateways with a hardened, X25519-only cipher profile;
  • CI runners and build containers on old or hand-tuned images;
  • in-house tools built on a TLS library pinned to a single curve;
  • integrations and bots calling the GHE.com API from locked-down networks.

When one of these fails it will look like a network outage: clones, pushes over HTTPS, API calls and webhooks deliveries through that path stop, while SSH keeps working.

What to do before 7 October

  • Check proxy and appliance TLS profiles used for GHE.com traffic. Make sure P-256 is offered; P-384 may be added too.
  • Remove any X25519-only setting from client configuration, runtime flags and TLS library options.
  • Update operating systems, runtimes, GitHub CLI and TLS libraries on runners and servers to supported versions.
  • Test from each network path before the date, for example by forcing P-256 in a test client, and fix any path that cannot negotiate it.
  • If you are unsure, GitHub asks customers to contact GitHub Support to validate their TLS configuration.

Sources

Categories & features