• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved Plesk not support Forward Secrecy

T

timscha

Guest
Hello!

Right now, I'm testing a brand new installation of Plesk on Debian 9.
I did a SSL check on ssllabs and got downgraded to B because Forward Secrecy is not supported.

What I did - for every domain:

- Using nginx
- Activate SSL using the SSLit extension
- activated HSTS and OCSP Stapling
- Using modern TLS versions and ciphers by Mozilla

Maybe someone has an idea how to fix this?

Thanks
 
I have A+ rating there for my domain and Plesk Obsidian and the same configs with Let'sEncrypt certificate. The difference only in OS - I have CentOS7 there.
What is the output of the following command:

$ curl -s -D- https://your.domain.tld | grep strict

?
 
Really interesting. I fixed it by re-running the mozilla sync. Now I got an A+ :)
 
Back
Top