Hi there
Got a security alert sent to me by one of my clients that their site which is running on NGINX using the standard Wordpress web template in Hestia is showing TLS 1.0 and 1.1 are still enabled.
I checked two other sites on the same Hestia install and one of them also had 1.0 and 1.1 enabled while the 3rd site had them disabled.
In the main nginx.conf I see that only 1.2 and 1.3 are enabled and I haven’t modified any of the templates so trying to figure out how this is happening.
Any ideas on where I can check this or somehow force them to be disabled on a global level (which I thought it was already doing)?
So basically confirms I believe what I said earlier which is that I don’t have it set anywhere else. I am only using the stock web templates that came with Hestia.
Extra weird that some sites on the server are fine and others are listed as using 1.0 and 1.1. Just unsure how something could be bypassing the NGINX directives.
please if you can help i installed default configuration so Apache and nginx where installed for me sorry for this reasons here I’m afraid to share links
I could help if I’ve info. By default, nginx provided by Hestia only uses TLS 1.2 and 1.3 so I don’t know if you modified something, you are using a CDN, etc.
Can confirm that a domain running on ‘straight hestia’ has 1.0 and 1.1 disabled. But if you add Cloudflare proxy in front of that, it adds 1.0 and 1.1 back in.