How to get a Score of 100 on SSL labs
Information
Summary: |
How to get the highest score/rating on SSL labs for cipher strength. |
Environment: |
Product: LoadMaster Version:7.2.57 Platform: Application: |
Question/Problem Description: |
Strengthening the ciphers on a Virtual Service (VS) to give the highest score on SSL labs. |
Steps to Reproduce: | |
Error Message: | |
Defect Number: | |
Enhancement Number: | |
Cause: |
The default settings on an SSL offloaded VS will give an "A" rating with a protocol strength of 100 and a cipher strength of 90 when using TLS 1.2/1.3 only and best practices cipher suite. See image below |
Resolution: |
By Adjusting the Cipher list it is possible to secure a 100 score for ciphers on SSL labs. Please note that with security settings this high some older client Operating System's (OS's) and Applications may not be able to connect to the virtual service. As always balance security with availability for the service.
Go to "Certificates & Security -> Cipher Sets" Filter by "Best Practices" cipher set Remove ciphers from the current “Best Practices” cipher list until the following 5 are all that remains:
Then save as new cipher set as: "BestPracticesHIGH"
Then apply that cipher set to a virtual service that is offloaded/re-encrypted under SSL properties.
Then Deselect the three 128bit ciphers under TLS 1.3 settings Deselect:
Now run the SSL labs test again and it should now have 100 as the score for Cipher Strength. |
Workaround: | |
Notes: |
SSL Accelerated Service: https://support.kemptechnologies.com/hc/en-us/articles/6263740012301-SSL-Accelerated-Services
|