mozilla-it / sumo-infra

Infrastructure for support.mozilla.org
1 stars 3 forks source link

Ensure TLS cipher suites are current #21

Open kfferrando opened 5 years ago

kfferrando commented 5 years ago

There is concern that GoogleBot could delist the site if current TLS ciphers are not honored, specifically TLS 1.2. We should ensure we have a good mix of future proofing and backwards compatibility.

ziegeer commented 5 years ago

Also specifically disable older TLS on the CDNs.

kfferrando commented 5 years ago

We currently get an "A" rating from Qualys SSL scan and support 1.2. We just need to address the older ciphers as per previous comment.