SSL Labs Server Test is an online testing tool provided by Qualys. It comprehensively tests the certificate chain, security, performance, and protocol details of HTTPS websites, and gives a score, detailed test report, and improvement suggestions after the test is completed. Here are some key information about SSL Labs Server Test:
- Test content:
- SSL Labs Server Test analyzes the SSL/TLS configuration of the website, including supported protocol versions, cipher suites, certificate chains, key exchange algorithms, session resumption mechanisms, etc.
- Rating criteria:
- SSL Labs scores the security of the website based on the test results, and the scoring criteria will be updated as security practices evolve. For example, in the 2020 scoring criteria, TLS 1.0 and TLS 1.1 are considered insecure, so servers that support these protocols will receive lower scores.
- Testing rules overview:
- SSL Labs changed the algorithm in 2020, mainly modifying the scoring criteria for TLS 1.0 and TLS 1.1, because these older protocols use weak encryption algorithms and systems, such as SHA-1 and MD5, and have major security vulnerabilities.
- Browser support:
- Mainstream browsers such as Microsoft IE and Edge, Mozilla Firefox, Safari/Webkit, and Google Chrome are all planning to remove support for TLS 1.0 and TLS 1.1 in early 2020.
- Secrets to get an A+ rating:
- In order to get an A+ rating in the SSL Labs Server Test, the server configuration needs to support TLS 1.2 and TLS 1.3, enable HSTS (HTTP Strict Transport Security), do not display warnings, support TLS_FALLBACK_SCSV, and configure the appropriate cipher suite.
- Testing Tools:
- In addition to the online testing tools, SSL Labs also provides TestSSLServer, which is part of the SSL Labs Server Test that can be downloaded and run locally to test the SSL/TLS configuration of internal sites.
- Best Practices:
- SSL Labs recommends using a comprehensive SSL/TLS assessment tool to verify the configuration to ensure that the website is secure from the beginning, and to perform regular assessments to maintain security.
With SSL Labs Server Test, website administrators can understand the SSL/TLS configuration of the website and make adjustments based on the test results and recommendations to improve the security of the website.