I'll take a look at our configs tomorrow ๐
this post was submitted on 07 Aug 2023
9 points (80.0% liked)
sh.itjust.works Main Community
7705 readers
6 users here now
Home of the sh.itjust.works instance.
founded 1 year ago
MODERATORS
Were we outdated? I see we're using TLS 1.3 right now, and at least the certificate was last created/renewed before this post (created July 16, post on Aug 6). I know that's not really a metric, but my browser at least has the minimum TLS version set to 3, so I would absolutely have noticed if SJW used anything older.
I guess it's possible we allowed older TLS versions, but at least the version I'm connecting with is completely fine.
What about TLS 1.2?
Should still be good for now
Not really, here's why:
- weak ciphers
- SCSV (protocol fallback)
That's why I didn't go for that thankless job.