Home > SSL/TLS Best Practices – Dev

SSL/TLS Best Practices – Dev

The ultimate resource for optimal SSL/TLS configuration

Browse our SSL/TLS Configuration guides to achieve the optimal performance and cybersecurity trust. We’ve covered the most important configurations and best practices and have included specific how-to information for a variety of server types. Choose your tech stack to find articles that only include those solutions.

Download SSL/TLS Best Practices Checklist

Expert Guides

Read deep-dives on Specific SSL/TLS Best Practices

SSL/TLS Best Practices Statistics

How well does the internet implement SSL/TLS best practices?

Basic Configuration Guides by Server Type

SSL/TLS Configuration Guides:

SSL/TLS Configuration Statistics

When you visit a website that displays the padlock, you might assume it’s secure. But how many of those sites have actually configured secure encryption? How many websites follow basic SSL/TLS best practices? We took the top 100 websites (by traffic) and compared their SSL/TLS configurations to a random cross-section sites across the web. See how they stack up:

SSL/TLS Best PracticeTop 100 websitesRandom Cross-section
Disabled SSL V2100%99.82%
Disabled SSL V399%98.42%
Has TLS 140%23.47%
Has TLS 1.141%25.04%
Has TLS 1.2100.00%60.42%
Has TLS 1.386%60.77%
HSTS Offered55%16.81%
HSTS Preload Enabled30%0.09%
Has CAA RecordN/A4.38%
Has OCSP StaplingN/A35.55%
http redirects to https71%76.97%
Has Intermediate CertificateN/A72.24%

SSL/TLS Deployment Best Practices Course:

Learn the basic components of SSL/TLS configuration by Ivan Ristić, the author of SSL Labs. Taken from his book Bulletproof SSL and TLS, the following video covers the configuration best practices of Keys, Certificates, Protocols, Suites, and more!

Video Contents:

  • Keys: Algorithms, Size, & Management
  • Certificates: Validation, Hostnames, Sharing, Lifetime, Signature Algorithms, & Chain Correctness
  • Protocol Configuration
  • SSL Pulse: Protocol Support, Forward Secrecy
  • Suites: Configuration, Compatibility, &  New Suites Coming Soon