← Back to Articles
Guide2026-04-08•11 min read

SSL Security Best Practices

· CSR.plus Team

SSL Security Best Practices
  • •Serve TLS 1.3 and deprecate everything older than TLS 1.2 as soon as analytics allow.
  • •Enable HSTS to force HTTPS and block downgrade attacks; add it to the HSTS preload list for full protection.
  • •Protect the private key, automate renewal, and verify with our SSL Checker after every change.
80%
TLS 1.3 adoption
of top sites support it in 2026
Free
HSTS preload
hardcoded protection in browsers
90 days
Key rotation
with every certificate renewal

Protocols: modern only

Enable TLS 1.3 and TLS 1.2, and disable everything older — SSLv3, TLS 1.0 and TLS 1.1 are all broken or deprecated. Once your logs show no TLS 1.2 traffic, drop it too. In Nginx set ssl_protocols TLSv1.2 TLSv1.3; in Apache SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1.

Cipher suites and forward secrecy

Use modern AEAD ciphers such as TLS_AES_256_GCM_SHA384 and prefer ECDHE or DHE key exchange for forward secrecy. With TLS 1.3, forward secrecy is mandatory and cipher choice is handled by the protocol, which makes this configuration mostly automatic.

HSTS

The Strict-Transport-Security header tells browsers to use HTTPS only for your domain, preventing downgrade and cookie-hijacking attacks. Start with max-age=31536000; includeSubDomains; preload, then submit your domain to the HSTS preload list so protection is hardcoded into browsers.

OCSP stapling

Stapling lets your server attach a timestamped proof of certificate validity to the handshake, removing a separate OCSP request for every visitor. It improves both privacy and latency. Enable it in Nginx with ssl_stapling on and verify with our SSL/TLS Tracer.

Key protection and renewal

Store private keys with 600 permissions, never share them, and rotate them on every renewal. Automate renewal with an ACME client so 90-day certificates renew themselves. After each change, run our SSL Checker to confirm the configuration is still healthy.

FAQ

Is TLS 1.2 still acceptable?

For now it is the compatibility floor, but browsers will disable it in early 2027. Upgrade to TLS 1.3 now and plan to drop TLS 1.2 after a transition period.

Does HSTS slow down my site?

No. It only adds one small response header, while eliminating insecure requests and an extra redirect for returning visitors.

How often should I rotate keys?

With 90-day certificates, a fresh key per renewal is the norm. Rotate immediately if there is any sign of key exposure.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles