0

As TLS version v1.0 and v1.1 is outdated am just disabling these version and need to enable the v1.3 in Nginx webserver.

I added tls v1.2 v1.3 in main nginx.conf file and changed the options-ssl-nginx.conf for tls v1.2 v1.3 my options-ssl-nginx.conf file as below

# This file contains important security parameters. If you modify this file
# manually, Certbot will be unable to automatically provide future security
# updates. Instead, Certbot will print and log an error message with a path to
# the up-to-date file that you will need to refer to when manually updating
# this file.

ssl_session_cache shared:le_nginx_SSL:1m;
ssl_session_timeout 1440m;

ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;


ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;

I modified this by referring to below link,

https://ssl-config.mozilla.org/#server=nginx&version=1.18.0&config=intermediate&openssl=1.1.1k&guideline=5.6

Now I can disable the older versions but v1.3 is not enabled yet

Are there any options to enable TLS v1.3 in GoDaddy or we can add it from the server configuration?

How can I enable the TLS v1.3 to the godaddy SSL certificate.ANy guidance is much appreciated

Thanks!

jayaprakash R
  • 152
  • 3
  • 13
  • 1
    What versions of `nginx` and `openssl` do you use? –  Apr 09 '22 at 16:13
  • The available TLS version is determined by the used web server and SSL library, not by the certificate. If TLS 1.3 does not show up this usually means you are using old versions of nginx and openssl. – Robert Apr 10 '22 at 10:59
  • I am using nginx version nginx/1.18.0 and openssl v1.1.1. And this openssl and nginx version supports tls v1.3 right? as I mentioned in question I changed tls version in main nginx config file and letsencryt config file and changes SSL cipher also but its not show up tls v1.3 when I check with ssllab website and other SSL checker websites – jayaprakash R Apr 11 '22 at 05:11

0 Answers0