Re: https://www.modsecurity.org/ TLS 1.0

Reindl Harald <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Organization the lounge interactive design
Message-ID <[email protected]>

Am 12.03.20 um 17:57 schrieb Reindl Harald:
> https://www.modsecurity.org/
> 
> seriously?
> 
> it's not a breaking news that firefox and other browsers are planning
> disable TLS1.0/1.1 for many months

https://i.imgur.com/wC4IJbs.png shows the by far the dumbest webserver
setup i have faced in the past 15 years

The server supports only older protocols, but not the current best TLS
1.2. Grade capped to C.

This server accepts RC4 cipher, but only with older protocols. Grade
capped to B.

This server does not support Forward Secrecy with the reference
browsers. Grade capped to B.

This server does not support Authenticated encryption (AEAD) cipher
suites. Grade capped to B.

This server supports TLS 1.0. Grade capped to B.

------------------------

and yes *i know* that we are *currently* Grade B because *allowing* TLS
< 1.2 for now for a short time to redirect support calls of endusers as
dumb as your webadmins to somewhere else

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
ssllabs.png (image/png, 66.3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.