Please stop using TLS v1.0 and 1.1

https://blog.qualys.com/product-tech/2018/11/19/grade-change-for-tls-1-0-and-tls-1-1-protocols

9 points · 5 comments · view on lemmy.world

5 Comments

biela@sh.itjust.works · 3 pts · 3y (1 reply)

I'll take a look at our configs tomorrow 👍

sugar_in_your_tea@sh.itjust.works · 1 pts · 3y

Were we outdated? I see we're using TLS 1.3 right now, and at least the certificate was last created/renewed before this post (created July 16, post on Aug 6). I know that's not really a metric, but my browser at least has the minimum TLS version set to 3, so I would absolutely have noticed if SJW used anything older.

I guess it's possible we allowed older TLS versions, but at least the version I'm connecting with is completely fine.

mypasswordis1234@lemmy.world · 3 pts · 3y (2 replies)

What about TLS 1.2?

pastermil@sh.itjust.works · 4 pts · 3y (1 reply)

Should still be good for now

xaera@sh.itjust.works · 2 pts · 3y

Not really, here's why:

  • weak ciphers
  • SCSV (protocol fallback)

That's why I didn't go for that thankless job.