[SSL Observatory] TLS 1.1/1.2 support

Erwann ABALEA erwann at abalea.com
Mon Aug 22 00:35:33 PDT 2011


2011/8/22 Peter Gutmann <pgut001 at cs.auckland.ac.nz>:
> Erwann ABALEA <erwann at abalea.com> writes:
>
>>If the client used OpenSSL, then TLS1.0 was the max version it could detect
>>(and in this case, then 1.1 is an error). Same goes for Apache+mod_ssl.
>
> Ah, OK.  So the previous figure really needs to come with a disclaimer to say
> that it's not necessarily representative of real-world statistics :-).

There was a condition (if), as I haven't read the source code (or I
don't remember what I read, that's also possible) :)

SSLLabs from Qualys gives a rating of your website SSL configuration,
after some tests. It can also detect TLS1.1/1.2, and detect a bogus
answer to a nonexistent TLS version (3.99).

-- 
Erwann.



More information about the Observatory mailing list