SSL Labs A+ Rating - Ideal settings

shoulders

Registered
Oct 20, 2008
3
0
51
Hi

I am a newbie to ciphers and the like but I would like to score A+ on SSL Labs but the default settings of cPanel do not achieve this. I also want to make the other services really secure but I have not found a cheatsheet with them all on.

Does anyone have an upto date/custom/official set of configurations of the following settings so I can secure my server (cPanel v82.0.7) to modern standards:

Apache
  • Home »Service Configuration »Apache Configuration »Global Configuration » SSL Cipher Suite
  • Home »Service Configuration »Apache Configuration »Global Configuration » SSL/TLS Protocols
cPanel Web Disk
  • Home »Service Configuration »cPanel Web Disk Configuration»TLS/SSL Cipher Suite
  • Home »Service Configuration »cPanel Web Disk Configuration»TLS/SSL Protocols
cPanel Web Services
  • Home »Service Configuration »cPanel Web Services Configuration»TLS/SSL Cipher List
  • Home »Service Configuration »cPanel Web Services Configuration»TLS/SSL Protocols
Exim
  • Home »Service Configuration »Exim Configuration Manager »Options for OpenSSL
  • Home »Service Configuration »Exim Configuration Manager »SSL/TLS Cipher Suite List
FTP
  • Home »Service Configuration »FTP Server Configuration »TLS Encryption Support
  • Home »Service Configuration »FTP Server Configuration »TLS Cipher Suite
Mail Server
  • Home »Service Configuration »Mailserver Configuration »SSL Cipher List
  • Home »Service Configuration »Mailserver Configuration »SSL Minimum Protocol
Thanks

Shoulders


 

shoulders

Registered
Oct 20, 2008
3
0
51
thanks for the info, but I was kind of hoping for a big list to drop in becasue I amn new to this. I am sure it would attract a lot of attention

similiar to this: zerosandones.co.uk/cpanel-pci-compliance/
 
Last edited by a moderator:

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,880
2,260
463
I also want to make the other services really secure but I have not found a cheatsheet with them all on.
I don't have a specific list to share with you in terms of getting A+ certified on SSL Labs, but the links on the document below are worth a read if you're interested in learning about security:


Beyond that, check out course or two at cPanel University sometime:


The team behind cPanel University works tirelessly to put out some really helpful training courses. Best of all, it's free.

Thank you.