Closed Darkspirit closed 5 years ago
Hello Jan,
Thanks for the report on our SSL certificate. We are currently using Heroku's automated SSL certs provided by Let's Encrypt, so we do not manage directly the certificate settings.
In the near future, we are moving to GCP with help from the Cloud Ops team, and should be able to use specific settings.
Found in Phabricator (and #2031), https://eventlistener.moz.tools has a suboptimal TLS config.
Please configure:
P-256
-only (secp256r1) would be fine.https://www.hardenize.com/report/coverage.testing.moz.tools/1559006499#www_tls
https://www.hardenize.com/report/static-analysis.testing.moz.tools/1559006590#www_tls
Thank you :)