As part of our ongoing commitment to platform security, Team Internet Group is introducing three changes to how registrars access our registry platform: mandatory two-factor authentication, stricter IP access controls, and the removal of outdated encryption standards. This article explains what's changing, when, and what you need to do to avoid disruption to your account or EPP access.
Key deadline: 29 September 2026. Most changes take effect on this date. One part of the 2FA change is already in effect.
1. Two-Factor Authentication (2FA)
What's changing
2FA is being rolled out in two phases:
| Phase | Effective | What changes |
|---|---|---|
| Phase 1 | Immediately | If 2FA is already enabled on a user account, it can no longer be disabled. |
| Phase 2 | 29 September 2026 | 2FA becomes mandatory for all users. There is no opt-out. |
What you need to do
- Enable 2FA for every user on your registrar console account now, ahead of the Phase 2 deadline.
- Once Phase 2 takes effect, any user without 2FA configured will be unable to log in until it is set up.
How to enable 2FA
- Log in to the registrar console.
- Go to Account Settings > Security.
- Select Enable Two-Factor Authentication.
- Follow the prompts to link an authenticator app or your preferred 2FA method.
(Confirm this navigation path matches the actual console UI before publishing.)
FAQs
Q: Can I disable 2FA after enabling it?
No. Once enabled, 2FA cannot be turned off, even before the Phase 2 deadline.
Q: What happens if my users don't have 2FA set up by 29 September 2026?
They will be locked out of the registrar console until 2FA is configured on their account.
Q: Does this apply to all users or just admins?
This applies to all users with access to the registrar console.
2. IP Whitelisting for EPP and Programmatic Access
What's changing
From 29 September 2026, EPP and other programmatic access to the registry will be restricted to IP addresses that have been explicitly whitelisted on your account. This applies to both IPv4 and IPv6.
What you need to do
- Review your current IP whitelist for every account you operate.
- Confirm all IP addresses your systems use for EPP or programmatic access are listed, including both IPv4 and IPv6 ranges where applicable.
- Add any missing IPs before 29 September 2026.
- If you use multiple accounts, note that whitelists are managed per account — a whitelist on one account does not extend to another.
How to update your IP whitelist
- Log in to the registrar console.
- Go to Account Settings > EPP Access (or equivalent section).
- Add or remove IP addresses as needed, ensuring both IPv4 and IPv6 entries are current.
- Save changes.
(Confirm this navigation path before publishing.)
FAQs
Q: What happens if my IP isn't whitelisted after 29 September 2026?
EPP and programmatic requests from non-whitelisted IPs will be rejected, resulting in loss of access.
Q: Is this whitelist shared across all my accounts?
No — each account maintains its own separate whitelist.
Q: Do I need to whitelist IPv6 even if I only use IPv4?
You only need to whitelist the IP versions you actually use to connect. If you use IPv4 only, whitelist your IPv4 addresses; the same applies to IPv6.
3. TLS Cipher Suite Deprecation (EPP Endpoint)
What's changing
In line with RFC 9325 (security recommendations for TLS), we are removing support for outdated, non-forward-secret and non-AEAD cipher suites on our EPP TLS endpoint, effective 29 September 2026. Connections using legacy ciphers will be rejected.
Ciphers no longer supported
- All plain RSA key-exchange suites (e.g.
AES128-GCM-SHA256,AES256-GCM-SHA384,AES128-SHA256,AES256-SHA256) - All CBC-mode ciphers (e.g.
ECDHE-RSA-AES128-SHA,ECDHE-RSA-AES256-SHA384,DHE-RSA-AES256-SHA256,AES128-SHA,AES256-SHA) - Camellia, ARIA, CCM_8, and 3DES variants
Supported ciphers going forward
TLS 1.2:
ECDHE-RSA-AES128-GCM-SHA256ECDHE-RSA-AES256-GCM-SHA384ECDHE-RSA-CHACHA20-POLY1305DHE-RSA-AES128-GCM-SHA256DHE-RSA-AES256-GCM-SHA384
TLS 1.3:
TLS_AES_256_GCM_SHA384TLS_CHACHA20_POLY1305_SHA256TLS_AES_128_GCM_SHA256
What you need to do
- Check your EPP client's TLS configuration.
- Confirm it is configured to negotiate one of the supported ciphers listed above.
- Update your client or library before 29 September 2026 if it currently relies only on a deprecated cipher.
FAQs
Q: How do I check which cipher my EPP client is using?
This depends on your client software/library. Most EPP client libraries (e.g. OpenSSL-based tools) allow you to specify or inspect the cipher suite in their TLS configuration. If you're unsure, share your client/library name and version with support and we can advise.
Q: What happens if my client only supports a deprecated cipher?
Your EPP connection will fail from 29 September 2026 until the client is reconfigured or updated to support one of the listed ciphers.
Q: Why is this change happening?
It aligns our EPP TLS endpoint with RFC 9325 best practices, removing weaker cipher suites that lack forward secrecy or authenticated encryption.
Summary Timeline
| Date | Change |
|---|---|
| Immediate | 2FA cannot be disabled once enabled (Phase 1) |
| 29 September 2026 | 2FA mandatory for all users (Phase 2) |
| 29 September 2026 | IP whitelisting enforced for EPP/programmatic access |
| 29 September 2026 | Legacy cipher suites rejected on EPP TLS endpoint |
Need Help?
If you need assistance enabling 2FA, updating your IP whitelist, or configuring your EPP client's TLS settings, contact us and we'll be happy to help.