Zoomtopia is here. Unlock the transformative power of generative AI, helping you connect, collaborate, and Work Happy with AI Companion.
Register nowEmpowering you to increase productivity, improve team effectiveness, and enhance skills.
Learn moreKeep your Zoom app up to date to access the latest features.
Download Center Download the Zoom appDownload hi-res images and animations to elevate your next Zoom meeting.
Browse Backgrounds Zoom Virtual BackgroundsEmpowering you to increase productivity, improve team effectiveness, and enhance skills.
Zoom AI CompanionUser groups are unique spaces where community members can collaborate, network, and exchange knowledge on similar interests and expertise.
Help & Resources is your place to discover helpful Zoom support resources, browse Zoom Community how-to documentation, and stay updated on community announcements.
The Events page is your destination for upcoming webinars, platform training sessions, targeted user events, and more. Stay updated on opportunities to enhance your skills and connect with fellow Zoom users.
2025-10-13 04:05 AM
Hi Zoom Developer Community,
I’m currently in the process of submitting my app for Beta Testing on the Zoom Marketplace.
After completing all mandatory requirements and switching the environment to Production, my app failed the Security and Privacy Compliance Review with the following message:
“We noticed your app supports TLS 1.0 & TLS 1.1, which are considered insecure. Please consider ceasing/upgrading these versions.”
However, I’ve verified multiple times that:
TLS 1.0 and 1.1 are completely disabled on our servers.
Only TLS 1.2 and 1.3 are enabled for all inbound and outbound HTTPS traffic.
The backend (Node.js / NestJS) runs behind a reverse proxy with strict SSL configuration.
We’ve attached full configuration and connection test screenshots in our reply to the Marketplace team as proof, but the review still failed.
I’d really appreciate if anyone from the Zoom team or community could help clarify:
How does Zoom test or verify TLS protocol versions during app security review?
Could there be any specific endpoint or redirect Zoom checks that might cause this false flag?
Has anyone else encountered this issue during Beta or Production app review, and how did you resolve it?
We’ve been waiting quite a while for this process, so any insight or escalation would mean a lot.
Thanks in advance for your support and time!
Best,
2025-10-15 03:06 AM
It seems Zoom's Security scan may still be detecting legacy TLS endpoints, possibly from redirects, old sub-domains, or third-party dependencies. Even if your main server enforces only TLS 1.2 and TLS 1.3, ensure that all linked URLs, webhooks, and OAuth redirect URLs also disable TLS 1.0 and 1.1. You can verify this using tools like SSL Labs or the map script ssl-enum-ciphers. Double-check that your reverse proxy and load balancer configurations forward TLS correctly. Once all endpoints strictly support TLS 1.2 or higher, share the updated scan report and configuration details with the Zoom Marketplace team to clear the compliance review. I hope it may help!
2025-10-24 02:34 AM
If that Zoom should report what endpoint use 1.1 and 1.2, but there is no information at all