Score:1

Why enabling _only_ TLSv1.3 is a bad idea?

in flag

I have NGINX configured to only support TLS version 1.3 However when I go to https://check-your-website.server-daten.de/

It shows the error

Error creating a TLS-Connection: TLSv1.3 found, but no connection via TLSv1.2 possible. Please activate TLSv1.2

Isn't enabling only TLSv1.3 much safer? Why do we still need to enable TLSv1.2?

Score:1
cn flag

TLS 1.3 only, is possible with modern clients. Test with the oldest client version you will support for your users.

Mozilla's server TLS profiles and configuration generator remains a good resource.

D4v1dH03 avatar
in flag
Yeah, I guess SSL Labs is buggy then. A server that _only_ supports TLSv1.3 only gets an A, while a server that supports both TLSv1.3 and TLSv1.2 gets a A+
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.