Pfeiffer Szilárd
Balasys
ssl.use-sslv2 = "disable" ssl.use-sslv3 = "disable"
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
SSLProtocol all -SSLv2 -SSLv3
?TLSv1 !SSLv2 !SSLv3
TLS
_ECDHE
_RSA
_AES_CBC
_SHA
ssl.cipher-list = "CipherSuiteString"
ssl_ciphers CipherSuiteString
SSLCipherSuite CipherSuiteString
EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
honor-cipher-order = "enable"
ssl_prefer_server_ciphers on;
SSLHonorCipherOrder on
Always On
Certificate Revocation List
Online Certificate Status Protocol
Responders
Stapling
-
ssl_stapling on;
SSLUseStapling on
Should Be On
Automatic Redirect to HTTPS
Public Key Pinning
Defense against
Clickjacking
Content Injection Attacks
Cross-site scripting
setenv.add-response-header=("Strict-Transport-Security"=>"Value")
add_header Strict-Transport-Security "Value" always;
Header always set Strict-Transport-Security "Value"
max-age=63072000; includeSubdomains;
setenv.add-response-header=("Public-Key-Pins"=>"Value")
add_header Public-Key-Pins "Value" always;
Header always set Public-Key-Pins "Value"
pin-sha256="GRAH5Ex+kB4cCQi5gMU82urf..."; max-age=15768000; includeSubDomains
setenv.add-response-header=("X-Frame-Options"=>"Value")
add_header X-Frame-Options "Value" always;
Header always set X-Frame-Options "Value"
SAMEORIGIN
setenv.add-response-header=("X-XSS-Protection"=>"Value")
add_header X-XSS-Protection "Value" always;
Header always set X-XSS-Protection "Value"
X-XSS-Protection: 1; mode=block
setenv.add-response-header=("Content-Security-Policy"=>"Value")
add_header Content-Security-Policy "Value" always;
Header always set Content-Security-Policy "Value"
default-src https://same.domain:443
Checker
Online
HTBridge
Qualys
securityheaders.io
Offline
CipherScan
SSLyze