Requesting SSL Certificates can be a bit of a hassle, so today I’m going to show you how to easily generate SSL certificates with the help of OpenSSL and your CA of choice.
TLS
Disabling Insecure Ciphers on NGINX – NGINX Tricks Part 4
HTTPS is everywhere these days, but not many people think that much about which cipher suites are considered safe. Cipher suites determines what encryption algorithms are used to secure the communication over HTTPS, and as time goes on older cipher… Read More ›
Fixing SSL Labs Grade on F5 Big-IP – Enabling HSTS
This week, we’re going for the gold medal, that sweet sweet A+ grade on Qualys SSL Labs. And to achieve this lofty goal of ours, we’ll need to enable one thing, HSTS. This is no small task, and for the… Read More ›
Fixing SSL Labs Grade on F5 Big-IP – Custom Cipher Groups
As promised in my last post on F5 load-balancers, this weeks issue of the never-ending guide on how to keep your F5 Big-IPs in the good graces of Qualys SSL Labs will deal with TLSv1.3 demanding that we use cipher… Read More ›
Fixing SSL Labs Grade on F5 Big-IP – Enabling TLSv1.3
In my last post on F5 load-balancers, we disabled TLS v1 and v1.1 as a preemptive measure as SSL Labs is going to start capping your grade to B if you’re caught supporting these protocols after January 2020. In this… Read More ›
Fixing SSL Labs Grade on F5 Big-IP – Disabling TLSv1 and TLSv1.1
So, it’s again time to start worrying about your SSL Labs grade. Coming January 2020, any site still supporting TLSv1 and TLSv1.1 will have their grade capped to B. As we all know, this is unacceptable, so we’ll once again… Read More ›
Enabling HTTP/2 on NGINX – NGINX Tricks Part 3
As you might have heard, there’s a new version of HTTP out there that’s far superior to HTTP/1.1. I won’t go into what exactly has changed in HTTP/2, but it’s faster and more secure, and allows for some even more… Read More ›
Fixing SSL Labs Grade on F5 Big-IP – Weak Cipher Suites
Today we’ll take a look at fixing the error that kept us from getting a grade better than B last time. Last time we were left with this test result: “This server supports weak Diffie-Hellman (DH) key exchange parameters. Grade… Read More ›
Fixing SSL Labs Grade on F5 Big-IP – Certificate Chains
Today I’m starting a new series, which has the working title of “Fixing SSL Labs Grade on F5 Big-IP Load Balancers” which is a series on fixing the most common SSLLabs.com grade issues (We all want that A+, am I right?) when… Read More ›
Finally, a Way to Fix IIS SSL/TLS Support!
If you’ve managed HTTPS sites for any time, you’ve probably come across Qualys SSL Labs, which allows you to check that your certificates are installed correctly, and also check that your server is configured correctly. It also has the habit… Read More ›