<!DOCTYPE html> <html> <head> </head> <body> <p> I was able to get an A+ rating from ssllabs by using these simplified steps:<br /><br />At <strong>Home / Service Configuration / Apache Configuration / Global Configuration</strong>, I set:<br /><br /><strong>SSL Cipher Suite</strong>: <br />ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS<br /><br />SSL/TLS Protocols: All -SSLv2 -SSLv3 -TLSv1<br />(for my limited audience, I chose to disable TLSv1.0 but maybe not right choice for big public websites yet)<br /><br />Then at <strong>Home / Service Configuration / Apache Configuration / Include Editor, I edited Pre Main Include (All Versions)</strong> and pasted these two lines:<br /><br />Header always set Strict-Transport-Security "max-age=31536000; includeSubdomains;"<br />SSLHonorCipherOrder on<br /><br />I then rebuilt Apache and I'm getting A+ ratings. Note that I have a mix of always-SSL and never-SSL websites hosted on my server, and they all continue to work fine. The header Strict-Transport-Security is even returned on my never-SSL websites, which doesn't seem right, but the docs at Wikipedia say it is always ignored on non-SSL responses and that matches my experience so far. ssllabs shows the header being returned/recognized on my SSL websites.<br /><br />This blog post from last year also suggests editing Pre Main Include ( <a class="externalLink ProxyLink" href="https://kris.io/2015/12/11/getting-an-a-on-ssl-labs-test-in-5-minutes-on-cpanel/" target="_blank" rel="nofollow noopener" data-proxy-href="proxy.php?link=https%3A%2F%2Fkris.io%2F2015%2F12%2F11%2Fgetting-an-a-on-ssl-labs-test-in-5-minutes-on-cpanel%2F&hash=f95a6f12e7e161c9122493f873ed4df3">Getting an A+ on SSL Labs test in on all cPanel domains in 5 minutes – kris.io : virtualization & cloud</a> ) rather than directly editing conf files. I mention this since it's easier to edit Pre Main Include and it might persist better & avoid closing you off from future updates to the core conf templates.</p> </body> </html>
Subscribe
0 Comments
Oldest