Achieving high security

Introduction #

After implementing the following in ProVide it is now possible to configure the server to achieve a perfect score at Qualys SSL Labs official test.

  • Implemented support for HTTP Strict Transport Security.
  • Implemented support to individually enable/disable SSL/TLS protocols (SSL v2, SSL v3, TLS v1, TLS v1.1, TLS v1.2, TLS v1.3).
  • Implemented support for forward secrecy with most browsers.
  • Improved support for completely loading chain certificates including intermediate.
  • Improved support for individually enable/disable SSL/TLS ciphers.
  • Improved support for renegotiation (allow secure, disable client-initiated).
SSL-labs_A provide server

Requirements #

  • Latest version of ProVide
  • Purchased certificate with at least 4096 bit key using SHA256 encryption (not SHA1)

Instructions #

  1. Stop the ProVide service
  2. Browse to the ProVide installation directory.
  3. Place your intermediate certificate(s) inside the “certificates” folder.
  4. Open the “settings.ini” file
  5. Find [HTTPS Protocols] and [HTTPS Ciphers] and alter them to look like this:
    [HTTPS Protocols]
    “TLS v1.3”
    [HTTPS Ciphers]
    “ECDHE-RSA-AES256-GCM-SHA384”
  6. Save the file
  7. Start the ProVide service
  8. Run the SSL Test found here to see your results: SSL Test

Contact our Product Specialist

Fill in the form below to book a 30 min no-obligation consulting session.

I will reply within 24 hours.

General Inquiry

Fill in the form below and our team will be happy to assist you

Office Hours

Monday-Friday:
8:00am to 5:00pm (EST)

Address

Farsight Tech Nordic AB
Kaplansgatan 16B
3:e Våningen
541 34 Skövde

Free Trial

Get
ProVide Software