In the SSL Server Rating Guide, I see that a A+ is not rewarded to servers that don’t support TLS_FALLBACK_SCSV. My server (www.cauldron-vtt.net) doesn't support TLS_FALLBACK_SCSV, but it also doesn't support TLS v1.1 and lower. From my understanding, TLS_FALLBACK_SCSV is only for fallback from TLS v1.2 to lower. So, there is no point in supporting TLS_FALLBACK_SCSV when a server only supports TLS v1.2 and higher. Not rewarding an A+ should therefore not be done on this, right?
In the SSL Server Rating Guide, I see that a A+ is not rewarded to servers that don’t support TLS_FALLBACK_SCSV. My server (www.cauldron-vtt.net) doesn't support TLS_FALLBACK_SCSV, but it also doesn't support TLS v1.1 and lower. From my understanding, TLS_FALLBACK_SCSV is only for fallback from TLS v1.2 to lower. So, there is no point in supporting TLS_FALLBACK_SCSV when a server only supports TLS v1.2 and higher. Not rewarding an A+ should therefore not be done on this, right?