Forum Discussion

DimitriRosto_35's avatar
DimitriRosto_35
Icon for Nimbostratus rankNimbostratus
Feb 27, 2018

How to interpret SSL/TLS test results

Hi, everyone, We've checked recently our website (stopdrugs.info) using SSL/TLS security test. The report here revealed a lot of errors and vulnerabilities with overall grade B-. But now I don't know what to do with these results. Can anyone just make some short hints if there are any critical errors which are really essential for our website security. Thank you in advance.

 

4 Replies

  • eben's avatar
    eben
    Icon for Nimbostratus rankNimbostratus

    It means some of the cipher suites that are active are not PCI/HIPAA/NIST compliant. You could manually disable this set of cipher suites from your client ssl profile.This Resource will come handy.

     

    Secondly your websites calls third party resources using HTTP and not HTTPS. Resolving this should take you from a B- to A.

     

    HTH

     

  • It means some of the cipher suites that are active are not PCI/HIPAA/NIST compliant. You could manually disable this set of cipher suites from your client ssl profile.This Resource will come handy.

     

    Secondly your websites calls third party resources using HTTP and not HTTPS. Resolving this should take you from a B- to A.

     

    HTH