vendredi 23 janvier 2015

Hardening SSL/TLS on Azure Cloud Service for A+ on Qualys SSL Labs?



We're using this powershell script as our Azure Cloud Service (PaaS) startup script and we're at an A- on the Qualys SSL Labs test


Specifically we're losing points for the following reasons:



Forward Secrecy : With some browsers (more info)
Downgrade attack prevention : No, TLS_FALLBACK_SCSV not supported (more info)


We'd like to set it up for an A+ on that one (and improve other aspects not covered in that test). How can we do so?





Aucun commentaire:

Enregistrer un commentaire