SSL Security Best Practices
· CSR.plus Team

- •Serve TLS 1.3 and deprecate everything older than TLS 1.2 as soon as analytics allow.
- •Enable HSTS to force HTTPS and block downgrade attacks; add it to the HSTS preload list for full protection.
- •Protect the private key, automate renewal, and verify with our SSL Checker after every change.
Protocols: modern only
Enable TLS 1.3 and TLS 1.2, and disable everything older — SSLv3, TLS 1.0 and TLS 1.1 are all broken or deprecated. Once your logs show no TLS 1.2 traffic, drop it too. In Nginx set ssl_protocols TLSv1.2 TLSv1.3; in Apache SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1.
Cipher suites and forward secrecy
Use modern AEAD ciphers such as TLS_AES_256_GCM_SHA384 and prefer ECDHE or DHE key exchange for forward secrecy. With TLS 1.3, forward secrecy is mandatory and cipher choice is handled by the protocol, which makes this configuration mostly automatic.
HSTS
The Strict-Transport-Security header tells browsers to use HTTPS only for your domain, preventing downgrade and cookie-hijacking attacks. Start with max-age=31536000; includeSubDomains; preload, then submit your domain to the HSTS preload list so protection is hardcoded into browsers.
OCSP stapling
Stapling lets your server attach a timestamped proof of certificate validity to the handshake, removing a separate OCSP request for every visitor. It improves both privacy and latency. Enable it in Nginx with ssl_stapling on and verify with our SSL/TLS Tracer.
Key protection and renewal
Store private keys with 600 permissions, never share them, and rotate them on every renewal. Automate renewal with an ACME client so 90-day certificates renew themselves. After each change, run our SSL Checker to confirm the configuration is still healthy.
FAQ
Is TLS 1.2 still acceptable?
For now it is the compatibility floor, but browsers will disable it in early 2027. Upgrade to TLS 1.3 now and plan to drop TLS 1.2 after a transition period.
Does HSTS slow down my site?
No. It only adds one small response header, while eliminating insecure requests and an extra redirect for returning visitors.
How often should I rotate keys?
With 90-day certificates, a fresh key per renewal is the norm. Rotate immediately if there is any sign of key exposure.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.