To keep NSS in sync with the current security standards and expectations, and consistent to what OpenSSL now does, I think NSS should disable TLS below 1.2 by default. This is already done in Ubuntu, attached is the patch that implements the change. Thanks! Paride