![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
TLS 1.0/1.1 being phased out by browsers in 2 months. Are you ready?
There's a change coming in January 2020 which could result in problems with HTTPS sites.
![]() https://www.entrustdatacard.com/blog...eprecating-tls Your server needs to support at least TLS 1.2, and preferably also the current 1.3. If not, by early next year, people with modern (and updated) browsers will refuse to load your site. If you have a HTTPS site that's a few years old, you may need to upgrade the software, or modify your config. Wouldn't hurt to give everything a once-over anyway; my server already supported TLS 1.2, but I upgraded Apache so that I could enable TLS 1.3. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Not this shit again lol. I guess it will be enough to update package openssl ?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
Even though it's experimental the major browsers already support it. I saw 70%+ of IPs switch to 1.3 once I had upgraded. It's important to note that even though modern browsers have moved to TLS 1.2/1.3 by default, there's still some oddball and obsolete browsers which only support 1.0 or 1.1. So unless you're accepting credit card or personal info - the older versions are insecure - it may be worth considering still supporting those. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Bearing in mind the caveat I mentioned above, this page shows how to move forward and cleanly negotiate only TLS 1.2+
https://tecadmin.net/enable-tls-in-modssl-and-apache/ The important line in httpd.conf is SSLProtocol -all +TLSv1.2 +TLSv1.3 |
![]() |
![]() ![]() ![]() ![]() ![]() |