whonix.org server SSL settings enhancement

Information

ID: 917
PHID: PHID-TASK-kmwzdkkklbudumelczjm
Author: Patrick
Status at Migration Time: resolved
Priority at Migration Time: Normal

Description

@TNTBOMBOM

TLS 1.1 and CBC cipher considered weak now better to be deprecated for security reasons:

SSL Server Test: deb.whonix.org (Powered by Qualys SSL Labs)

Also now TLS 1.3 available with Lets Encrypt, is it good idea to support it ?

An Overview of TLS 1.3 - Faster and More Secure

Comments


Patrick

2021-12-09 14:45:30 UTC