Open doino-gretchenliev opened 6 years ago
Your certificate's public key is only 2048-bit RSA. The key exchange score comes from the strength of the ephemeral key exchange and the strength of the public key. You need a 4096-bit RSA (or 384-bit ECC) key on your certificate to get 100%.
Not sure whether it's there already, but I can't find this requirement in the documentation. Probably you need to add it. Thank you.
My web site is not reporting 'Key Exchange' 100 score even though I have cipher suite, that covers all tested browsers and DH parameter is reported to be 4096 bits. https://www.ssllabs.com/ssltest/analyze.html?d=www.gretchmedia.com&hideResults=on