3 ms·
AFAIK it's also impossible to get an A+ if you want to support older browsers and OSs (the intermediate and old settings from this site) due to BEAST. Seems lik
by jcoby 12y ago
AFAIK it's also impossible to get an A+ if you want to support older browsers and OSs (the intermediate and old settings from this site) due to BEAST. Seems like XP, Vista, and IE <= 9 were all affected by using the modern cypher suite from Mozilla (they all got a F).
I wasn't able to find a way to do server-side BEAST mitigation that didn't involve re-enabling RC4 ciphers (which is a far worse option). SSLLabs automatically downgrades any site that doesn't do BEAST mitigation to an A-.
I also was unable to get forward-secrecy working with all reference browsers using the intermediate setting.
- jvehent 12y agoI'm not sure how you got those results. I am certainly getting an A+ with the intermediate configuration and HAProxy. https://www.ssllabs.com/ssltest/analyze.html?d=jve.linuxwall.info https://www.ssllabs.com/ssltest/analyze.html?d=jve.linuxwall...
- jcoby 12y agoTurns out I was remembering wrong. The A- downgrade was from not supporting forward-secrecy in all reference browsers which is an issue with openssl than the recommended cipher suites.
- IgorPartola 12y agoI think it is impossible to max out the various bars in the bar graph with these configurations (at least up to intermediate), but you can easily get A+ with latest stable nginx and intermediate config.