3 ms·
I think one of the biggest pitfalls of SSL/TLS (and many other security technologies available now) is that they are so configurable and flexible. The approach
by ivanr 13y ago
I think one of the biggest pitfalls of SSL/TLS (and many other security technologies available now) is that they are so configurable and flexible. The approach assumes everyone has the knowledge and the time to invest to tune everything. In reality, few people do.
Going back to your request, it's impossible to do with server configuration alone. Many other aspects, including the design of the web application, play a significant role. The best we can do at this point is work on the body of knowledge, hoping others can find the time to invest.
The best I was able to do so far is build the SSL Labs test[1], write the SSL/TLS Deployment Best Practices guide[2], and start the SSL Research Wiki[3], where I intend to add other un-structured information over time (including example server configuration). I have also written a free OpenSSL Cookbook[4] (requires registration, and you can opt out of email afterwards).
Apologies if this post comes across as self-promoting, but this is what I spent a large amount of my time on. These are all genuinely useful and important resources.
[1] https://www.ssllabs.com/ssltest/ https://www.ssllabs.com/ssltest/
[2] https://www.ssllabs.com/projects/best-practices/ https://www.ssllabs.com/projects/best-practices/
[3] https://github.com/ssllabs/research/wiki https://github.com/ssllabs/research/wiki
[4] https://www.feistyduck.com/books/bulletproof-ssl-tls-and-pki/ https://www.feistyduck.com/books/bulletproof-ssl-tls-and-pki...
- pfg 13y agoThank you very much for your great work, I've found both the SSL Labs test and the best practice guide quite useful!