Starting 7 Oct 2026, GitHub Enterprise Cloud with data residency will reject any HTTPS client that only offers X25519 for key agreement. Engineers who rely on custom TLS stacks, proxies, or security appliances need to verify that P‑256 (secp256r1) or P‑384 (secp384r1) is enabled, otherwise their builds, CI jobs, or automation will fail to connect.
What changed
GitHub is ending support for X25519‑only key‑agreement in TLS handshakes on the GHE.com data‑residency endpoints. The service will continue to accept the FIPS‑approved groups P‑256 and P‑384. The restriction applies only to HTTPS traffic; SSH connections remain unaffected.
Why X25519 TLS support matters to engineers
Most modern browsers, operating systems, the GitHub CLI, and common TLS libraries already include P‑256, so the change is transparent for typical workloads. However, any component that has been explicitly configured to present only X25519 – such as a corporate proxy, a security appliance, or a custom TLS library – will be unable to negotiate a connection after the cut‑off date. This can break CI/CD pipelines, automated scripts, or internal tools that interact with GitHub Enterprise Cloud.
Implementation and operational implications
- Audit all TLS‑terminating components that connect to GHE.com for X25519‑only settings.
- Update operating systems, runtimes, the GitHub CLI, proxies, and TLS libraries to versions that enable P‑256 (or optionally P‑384) by default.
- Remove any configuration that restricts key‑agreement to X25519 only.
- Validate the handshake using a tool that can display the negotiated curve, ensuring that P‑256 or P‑384 appears.
- If validation fails, contact GitHub Support for assistance.
Related CloudNinjas coverage: security.
What This Means For Practitioners
Before 7 Oct 2026, verify that every client, proxy, or appliance that talks to GitHub Enterprise Cloud can negotiate P‑256 or P‑384. Adjust configurations or upgrade libraries as needed to avoid service disruption. Ongoing monitoring of TLS handshake logs will help catch any regressions after the deadline.
