Forum Discussion
Hannes_Rapp
Mar 18, 2016Nimbostratus
I don't think you will need RC4. If you can test, give a try to
ALL:!EXPORT:!RC4:!DES:!ADH:!EDH:!SSLv3
-This SSL/TLS config also complies with PCI DSS 3.0 (Enforced till the end of June 2016)
Although the string above qualifies for grade A in Qualys SSL labs, it's not perfect from a security standpoint. Windows Vista and XP clients on IE8 and newer can connect using TLS1.0 in combination with CBC.