6 ms·
Author here, please let me know any comments, issues or anything else. I'm also behind other projects like an SSL (site) test, a fast one: https://ssldecoder.o
by mdewinter 10y ago
Author here, please let me know any comments, issues or anything else.
I'm also behind other projects like an SSL (site) test, a fast one: https://ssldecoder.org/ https://ssldecoder.org/ and a certificate monitoring service (reminds you before expiring): https://certificatemonitor.org/ https://certificatemonitor.org/.
Also my personal site describing my adventures in *NIX and cloudland: https://raymii.org/s/ https://raymii.org/s/, plus a boatload of TLS related articles.
The mozilla guide is also very good, the ability to configure based on your server settings and browser support is a heck of a nice feature. Whenever I have time to learn javascript that's the first thing to implement.
Although, all my projects are open source (https://github.com/RaymiiOrg/ https://github.com/RaymiiOrg/) so merge requests are welcome. Ferm GPL believer here.
- mg794613 10y ago"Hier niet poepen zegmaar." I'd remove that to prevent confusion as it did with me ;)
- vtlynch 10y agoHow often are the recommendations on cipherli.st updated?
- mdewinter 10y agoNot very often, mostly when someone sends a merge request with a new piece of software (like varnish).
- AdamJacobMuller 10y agoOne of the things I noticed was that there is no rationale listed for the ssl_session_tickets disablement. I assume your concern is something like https://www.imperialviolet.org/2013/06/27/botchingpfs.html https://www.imperialviolet.org/2013/06/27/botchingpfs.html which for most general use cases you're correct in saying that it should be disabled, but, it definitely deserves a nuanced explanation.
- rajjalan 10y agoHi mdewinter, FYI, getting a cert error getting to cipherli.st