We’ve recently been testing sites with the Qualsys SSL Server Test here: https://www.ssllabs.com/ssltest/index.html
By default, the SSL settings on Vesta are good – but it’s not possible to get an A+ rating without making some changes to the nginx configuration files.
Although SSL Labs do give an indication as to where the SSL rating is low, it’s not very easy to see exactly what needs to be changed with nginx to get the A+ rating. The key things to improve:
- Limit the SSL ciphers that can be used
- Add HTTP Strict Transport Security with long duration
- Enable SSL stapling
Firstly, you have to SSH onto your vesta server, and edit the main nginx conf file: