HTTPS

From Rixort Wiki
Revision as of 16:33, 25 September 2019 by Paul (Sọ̀rọ̀ | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Ways to improve HTTPS connections

  • DNS CAA records - these restrict which certificate authorities are valid for the domain.
  • Support TLSv1.3
  • Do not support SSLv3 or lower
  • Disable support for TLS 1.0 and TLS 1.1, but beware of incompatible clients

Links