SSL/TLS Deployment Best Practices

SSL/TLS seems simple, you go to a CA to prove who you are they give you a credential, you install it on your server, turn on SSL and then you are done.

Unfortunately there is more to it than that, I recently had an opportunity to contribute to a Best Practices Guide (PDF)  that aims to provide clear and concise intructions to help administrators understand how to people deploy it securely.

The intention is to work on an advanced version of this document in the future that covers more details and advanced topics as well (think OCSP Stapling, SPDY, etc).

I hope you find it useful.

One thought on “SSL/TLS Deployment Best Practices

  1. Larry West

    The v1.0 PDF dates from 2012, which doesn’t seem so long ago, but, at a glance, the “Bulletproof SSL and TLS” book (ch. 8) has completely rewritten and updated the info in this PDF.

    I think it would be helpful to people who find this page to have a little note pointing them to and perhaps to v1.3 of this PDF, at

    Thanks again for the great resources. Just starting on the book.



Leave a Reply

Your email address will not be published. Required fields are marked *