HTTPS αž˜αž·αž“αžαŸ‚αž„αžαŸ‚αž˜αžΆαž“αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αžŠαžΌαž…αžŠαŸ‚αž›αžœαžΆαž αžΆαž€αŸ‹αžŠαžΌαž…αž‡αžΆαž“αŸ„αŸ‡αž‘αŸαŸ” αž—αžΆαž–αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αžαŸ’αžšαžΌαžœαž”αžΆαž“αžšαž€αžƒαžΎαž‰αž“αŸ…αž€αŸ’αž“αž»αž„ 5,5% αž“αŸƒαž‚αŸαž αž‘αŸ†αž–αŸαžš HTTPS

HTTPS αž˜αž·αž“αžαŸ‚αž„αžαŸ‚αž˜αžΆαž“αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αžŠαžΌαž…αžŠαŸ‚αž›αžœαžΆαž αžΆαž€αŸ‹αžŠαžΌαž…αž‡αžΆαž“αŸ„αŸ‡αž‘αŸαŸ” αž—αžΆαž–αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αžαŸ’αžšαžΌαžœαž”αžΆαž“αžšαž€αžƒαžΎαž‰αž“αŸ…αž€αŸ’αž“αž»αž„ 5,5% αž“αŸƒαž‚αŸαž αž‘αŸ†αž–αŸαžš HTTPS
αž‚αŸαž αž‘αŸ†αž–αŸαžšαž€αŸ†αž–αžΌαž›αž˜αž½αž™αžšαž”αžŸαŸ‹ Alexa (αžšαž„αŸ’αžœαž„αŸ‹αž€αžŽαŸ’αžαžΆαž›) αž’αžΆαž“αžΆαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αžŠαŸ„αž™ HTTPS αž‡αžΆαž˜αž½αž™αž“αžΉαž„αžŠαŸ‚αž“αžšαž„ (αž–αžŽαŸŒαž”αŸ’αžšαž•αŸαŸ‡) αž“αž·αž„αž—αžΆαž–αž’αžΆαžŸαŸ’αžšαŸαž™ (αž–αžŽαŸŒαžŸ) αž€αŸ’αž“αž»αž„αž…αŸ†αžŽαŸ„αž˜αž“αŸ„αŸ‡αž˜αžΆαž“αž‚αŸαž αž‘αŸ†αž–αŸαžšαžŠαŸ‚αž›αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡ (αž€αžΆαžšαžŠαžΆαž€αŸ‹αžŸαŸ’αžšαž˜αŸ„αž›αžŠαžΆαž…αŸ‹αŸ—)

αžŸαž–αŸ’αžœαžαŸ’αž„αŸƒαž“αŸαŸ‡ αžšαžΌαž”αžαŸ†αžŽαžΆαž„αž€αžΆαžšαžαž—αŸ’αž‡αžΆαž”αŸ‹αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– HTTPS αž”αžΆαž“αž€αŸ’αž›αžΆαž™αž‡αžΆαžŸαŸ’αžαž„αŸ‹αžŠαžΆαžš αž“αž·αž„αžŸαžΌαž˜αŸ’αž”αžΈαžαŸ‚αž‚αž»αžŽαž›αž€αŸ’αžαžŽαŸˆαž…αžΆαŸ†αž”αžΆαž…αŸ‹αž“αŸƒαž‚αŸαž αž‘αŸ†αž–αŸαžšαž’αŸ’αž„αž“αŸ‹αž’αŸ’αž„αžšαžŽαžΆαž˜αž½αž™αŸ” αž”αŸ’αžšαžŸαž·αž“αž”αžΎ αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžš αž”αžΆαžαŸ‹ αžŸαŸ’αž‘αžΎαžšαžαŸ‚αž‚αŸ’αžšαž”αŸ‹αž€αž˜αŸ’αž˜αžœαž·αž’αžΈαžšαž»αž€αžšαž€αž‘αžΆαŸ†αž„αž’αžŸαŸ‹αž”αž„αŸ’αž αžΆαž‰αž€αžΆαžšαž–αŸ’αžšαž˜αžΆαž“αž“αŸ„αŸ‡αŸ” αž€αžΆαžšαžαž—αŸ’αž‡αžΆαž”αŸ‹αž‘αŸ…αž‚αŸαž αž‘αŸ†αž–αŸαžšαž‚αžΊ "αž˜αž·αž“αž˜αžΆαž“αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–" αž αžΎαž™αž˜αž·αž“αžŽαŸ‚αž“αžΆαŸ†αž’αŸ„αž™αž•αŸ’αž‘αŸαžšαž–αŸαžαŸŒαž˜αžΆαž“αžŸαž˜αŸ’αž„αžΆαžαŸ‹αž‘αŸ…αžœαžΆαž‘αŸαŸ”

αž”αŸ‰αž»αž“αŸ’αžαŸ‚αžœαžΆαž”αŸ’αžšαŸ‚αžαžΆαžœαžαŸ’αžαž˜αžΆαž“αž“αŸƒ "αž…αžΆαž€αŸ‹αžŸαŸ„" αž“αŸ…αž€αŸ’αž“αž»αž„αžšαž”αžΆαžšαž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“αž˜αž·αž“αžαŸ‚αž„αžαŸ‚αž’αžΆαž“αžΆαž€αžΆαžšαž€αžΆαžšαž–αžΆαžšαž‘αŸαŸ” αž–αž·αž“αž·αžαŸ’αž™αž˜αžΎαž›αž‚αŸαž αž‘αŸ†αž–αŸαžšαžˆαžΆαž“αž˜αž»αžαž‚αŸαž…αŸ†αž“αž½αž“ 10 αž–αžΈαž€αžΆαžšαžœαžΆαž™αžαž˜αŸ’αž›αŸƒ Alexa αž”αžΆαž“αž”αž„αŸ’αž αžΆαž‰αžαžΆαž–αž½αž€αž‚αŸαž—αžΆαž‚αž…αŸ’αžšαžΎαž“αž‘αž‘αž½αž›αžšαž„αž“αžΌαžœαž—αžΆαž–αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αžŸαŸ†αžαžΆαž“αŸ‹αž“αŸ…αž€αŸ’αž“αž»αž„αž–αž·αž’αžΈαž€αžΆαžš SSL / TLS αž‡αžΆαž’αž˜αŸ’αž˜αžαžΆαžαžΆαž˜αžšαž™αŸˆαžŠαŸ‚αž“αžšαž„ αž¬αž—αžΆαž–αž’αžΆαžŸαŸ’αžšαŸαž™αŸ” αž™αŸ„αž„αžαžΆαž˜αž’αŸ’αž“αž€αž“αž·αž–αž“αŸ’αž’αž“αŸƒαž€αžΆαžšαžŸαž·αž€αŸ’αžŸαžΆ αž—αžΆαž–αžŸαŸ’αž˜αž»αž‚αžŸαŸ’αž˜αžΆαž‰αž“αŸƒαž€αž˜αŸ’αž˜αžœαž·αž’αžΈαž”αžŽαŸ’αžαžΆαž‰αž‘αŸ†αž“αžΎαž” αž”αž„αŸ’αž€αžΎαž“αž•αŸ’αž‘αŸƒαžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαž™αŸ‰αžΆαž„αžαŸ’αž›αžΆαŸ†αž„αŸ”

αž›αž‘αŸ’αž’αž•αž›αžŸαŸ’αžšαžΆαžœαž‡αŸ’αžšαžΆαžœ

αž€αžΆαžšαžŸαž·αž€αŸ’αžŸαžΆαž“αŸαŸ‡αž’αŸ’αžœαžΎαž‘αžΎαž„αžŠαŸ„αž™αž’αŸ’αž“αž€αž‡αŸ†αž“αžΆαž‰αž˜αž€αž–αžΈαžŸαžΆαž€αž›αžœαž·αž‘αŸ’αž™αžΆαž›αŸαž™ Venice Ca' Foscari (αž”αŸ’αžšαž‘αŸαžŸαž’αŸŠαžΈαžαžΆαž›αžΈ) αž“αž·αž„αžŸαžΆαž€αž›αžœαž·αž‘αŸ’αž™αžΆαž›αŸαž™αž”αž…αŸ’αž…αŸαž€αž‘αŸαžŸ Vienna αŸ” αž–αž½αž€αž‚αŸαž“αžΉαž„αž”αž„αŸ’αž αžΆαž‰αžšαž”αžΆαž™αž€αžΆαžšαžŽαŸαž›αž˜αŸ’αž’αž·αžαž“αŸ…αž€αŸ’αž“αž»αž„αžŸαž“αŸ’αž“αž·αžŸαž·αž‘ IEEE αž›αžΎαž€αž‘αžΈ 40 αžŸαŸ’αžαžΈαž–αžΈαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– αž“αž·αž„αž―αž€αž‡αž“αž—αžΆαž– αžŠαŸ‚αž›αž“αžΉαž„αž”αŸ’αžšαž–αŸ’αžšαžΉαžαŸ’αžαž‘αŸ…αž“αŸ…αžαŸ’αž„αŸƒαž‘αžΈ 20-22 αžαŸ‚αž§αžŸαž—αžΆ αž†αŸ’αž“αžΆαŸ† 2019 αž“αŸ…αžŸαžΆαž“αŸ‹αž αŸ’αžœαŸ’αžšαžΆαž“αŸ‹αžŸαŸŠαžΈαžŸαŸ’αž€αžΌαŸ”

αž‚αŸαž αž‘αŸ†αž–αŸαžš HTTPS αž”αž‰αŸ’αž‡αžΈαžˆαŸ’αž˜αŸ„αŸ‡ Alexa αž€αŸ†αž–αžΌαž› 10 αž“αž·αž„αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αžŠαŸ‚αž›αž–αžΆαž€αŸ‹αž–αŸαž“αŸ’αž’αž…αŸ†αž“αž½αž“ 000 αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŸαžΆαž€αž›αŸ’αž”αž„αŸ” αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž‚αŸ’αžšαžΈαž”αžŠαŸ‚αž›αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αžαŸ’αžšαžΌαžœαž”αžΆαž“αžšαž€αžƒαžΎαž‰αž“αŸ…αž›αžΎαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“ 90 αž–αŸ„αž›αž‚αžΊαž”αŸ’αžšαž αŸ‚αž› 816% αž“αŸƒαž…αŸ†αž“αž½αž“αžŸαžšαž»αž”αŸ–

  • 4818 αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αžŠαŸ„αž™ MITM
  • 733 αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αž…αŸ†αž–αŸ„αŸ‡αž€αžΆαžšαžŒαž·αž‚αŸ’αžšαžΈαž” TLS αž–αŸαž‰αž›αŸαž‰
  • 912 αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αž…αŸ†αž–αŸ„αŸ‡αž€αžΆαžšαžŒαž·αž‚αŸ’αžšαžΈαž” TLS αžŠαŸ„αž™αž•αŸ’αž“αŸ‚αž€

αž‚αŸαž αž‘αŸ†αž–αŸαžšαž…αŸ†αž“αž½αž“ 898 αž‚αžΊαž”αžΎαž€αž…αŸ†αž αž‘αžΆαŸ†αž„αžŸαŸ’αžšαž»αž„αž…αŸ†αž–αŸ„αŸ‡αž€αžΆαžšαž›αž½αž…αž…αžΌαž› αž–αŸ„αž›αž‚αžΊαž–αž½αž€αž‚αŸαž’αž“αž»αž‰αŸ’αž‰αžΆαžαž±αŸ’αž™αž…αžΆαž€αŸ‹αž”αž‰αŸ’αž…αžΌαž›αžŸαŸ’αž‚αŸ’αžšαžΈαž”αžαžΆαž„αž€αŸ’αžšαŸ… αž αžΎαž™αž‚αŸαž αž‘αŸ†αž–αŸαžšαž…αŸ†αž“αž½αž“ 977 αž•αŸ’αž‘αž»αž€αž˜αžΆαžαž·αž€αžΆαž–αžΈαž‘αŸ†αž–αŸαžšαžŠαŸ‚αž›αž˜αžΆαž“αž€αžΆαžšαž€αžΆαžšαž–αžΆαžšαž˜αž·αž“αž›αŸ’αž’ αžŠαŸ‚αž›αž’αŸ’αž“αž€αžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαž’αžΆαž…αž’αŸ’αžœαžΎαž’αž“αŸ’αžαžšαž€αž˜αŸ’αž˜αž‡αžΆαž˜αž½αž™αŸ”

αž’αŸ’αž“αž€αžŸαŸ’αžšαžΆαžœαž‡αŸ’αžšαžΆαžœαž”αžΆαž“αžŸαž„αŸ’αž€αžαŸ‹αž’αŸ’αž„αž“αŸ‹αžαžΆ αž€αŸ’αž“αž»αž„αž…αŸ†αžŽαŸ„αž˜αž’αž“αž’αžΆαž“ 898 "αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŸαž˜αŸ’αžšαž”αžŸαž˜αŸ’αžšαž½αž›αž‘αžΆαŸ†αž„αžŸαŸ’αžšαž»αž„" αž˜αžΆαž“αž αžΆαž„αž›αž€αŸ‹αžαžΆαž˜αž’αŸŠαžΈαž“αž’αžΊαžŽαž·αž αžŸαŸαžœαžΆαž€αž˜αŸ’αž˜αž αž·αžšαž‰αŸ’αž‰αžœαžαŸ’αžαž» αž“αž·αž„αž‚αŸαž αž‘αŸ†αž–αŸαžšαž’αŸ†αŸ—αž•αŸ’αžŸαŸαž„αž‘αŸ€αžαŸ” αž‚αŸαž αž‘αŸ†αž–αŸαžš 660 αž€αŸ’αž“αž»αž„αž…αŸ†αžŽαŸ„αž˜ 898 αž‘αžΆαž‰αž™αž€αžŸαŸ’αž‚αŸ’αžšαžΈαž”αžαžΆαž„αž€αŸ’αžšαŸ…αž–αžΈαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αžŠαŸ‚αž›αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αŸ– αž“αŸαŸ‡αž‚αžΊαž‡αžΆαž”αŸ’αžšαž—αž–αž‚αŸ’αžšαŸ„αŸ‡αžαŸ’αž“αžΆαž€αŸ‹αž…αž˜αŸ’αž”αž„αŸ” αž™αŸ„αž„αžαžΆαž˜αž’αŸ’αž“αž€αž“αž·αž–αž“αŸ’αž’ αž—αžΆαž–αžŸαŸ’αž˜αž»αž‚αžŸαŸ’αž˜αžΆαž‰αž“αŸƒαž€αž˜αŸ’αž˜αžœαž·αž’αžΈαž”αžŽαŸ’αžαžΆαž‰αž‘αŸ†αž“αžΎαž”αž”αž„αŸ’αž€αžΎαž“αž•αŸ’αž‘αŸƒαžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαž™αŸ‰αžΆαž„αžαŸ’αž›αžΆαŸ†αž„αŸ”

αž”αž‰αŸ’αž αžΆαž•αŸ’αžŸαŸαž„αž‘αŸ€αžαž€αŸαžαŸ’αžšαžΌαžœαž”αžΆαž“αžšαž€αžƒαžΎαž‰αž•αž„αžŠαŸ‚αžšαŸ– 10% αž“αŸƒαž‘αž˜αŸ’αžšαž„αŸ‹αž€αžΆαžšαž’αž“αž»αž‰αŸ’αž‰αžΆαžαž˜αžΆαž“αž”αž‰αŸ’αž αžΆαž‡αžΆαž˜αž½αž™αž“αžΉαž„αž€αžΆαžšαž”αž‰αŸ’αž‡αžΌαž“αž–αŸαžαŸŒαž˜αžΆαž“αž”αŸ’αžšαž€αž”αžŠαŸ„αž™αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž– αžŠαŸ‚αž›αž‚αŸ†αžšαžΆαž˜αž€αŸ†αž αŸ‚αž„αžŠαž›αŸ‹αž€αžΆαžšαž›αŸαž…αž’αŸ’αž›αžΆαž™αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹ αž‚αŸαž αž‘αŸ†αž–αŸαžš 412 αž’αž“αž»αž‰αŸ’αž‰αžΆαžαž±αŸ’αž™αžŸαŸ’αž‘αžΆαž€αŸ‹αž…αžΆαž”αŸ‹ cookies αž“αž·αž„αž€αžΆαžšαž›αž½αž…αž™αž€ session αž αžΎαž™ 543 αž‚αŸαž αž‘αŸ†αž–αŸαžšαžαŸ’αžšαžΌαžœαž‘αž‘αž½αž›αžšαž„αž€αžΆαžšαžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαž›αžΎ cookie integrity (αžαžΆαž˜αžšαž™αŸˆ subdomains) .

αž”αž‰αŸ’αž αžΆαž‚αžΊαžαžΆαž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ‰αž»αž“αŸ’αž˜αžΆαž“αž†αŸ’αž“αžΆαŸ†αžαŸ’αž˜αžΈαŸ—αž“αŸαŸ‡αž“αŸ…αž€αŸ’αž“αž»αž„αž–αž·αž’αžΈαž€αžΆαžšαž“αž·αž„αž€αž˜αŸ’αž˜αžœαž·αž’αžΈ SSL / TLS αž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αž’αžαŸ’αžαžŸαž‰αŸ’αž‰αžΆαžŽαž—αžΆαž–αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αž˜αž½αž™αž…αŸ†αž“αž½αž“αŸ– POODLE (CVE-2014-3566), BEAST (CVE-2011-3389), CRIME (CVE-2012-4929), BREACH (CVE-2013-3587), αž“αž·αž„ Heartbleed (CVE-2014-0160)αŸ” αžŠαžΎαž˜αŸ’αž”αžΈαž€αžΆαžšαž–αžΆαžšαž”αŸ’αžšαž†αžΆαŸ†αž„αž“αžΉαž„αž–αž½αž€αžœαžΆ αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž˜αž½αž™αž…αŸ†αž“αž½αž“αžαŸ’αžšαžΌαžœαž”αžΆαž“αž‘αžΆαž˜αž‘αžΆαžšαž“αŸ…αž›αžΎαž•αŸ’αž“αŸ‚αž€αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ αž“αž·αž„αž•αŸ’αž“αŸ‚αž€αž’αžαž·αžαž·αž‡αž“ αžŠαžΎαž˜αŸ’αž”αžΈαž‡αŸ€αžŸαžœαžΆαž„αž€αžΆαžšαž”αŸ’αžšαžΎαž€αŸ†αžŽαŸ‚αžŠαŸ‚αž›αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αž…αžΆαžŸαŸ‹αŸ” αž”αŸ‰αž»αž“αŸ’αžαŸ‚αž“αŸαŸ‡αž‚αžΊαž‡αžΆαž“αžΈαžαž·αžœαž·αž’αžΈαžŠαŸ‚αž›αž˜αž·αž“αž˜αŸ‚αž“αž‡αžΆαžšαžΏαž„αžαžΌαž…αžαžΆαž…αž“αŸ„αŸ‡αž‘αŸ αž–αžΈαž–αŸ’αžšαŸ„αŸ‡αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž”αŸ‚αž”αž“αŸαŸ‡αž–αžΆαž€αŸ‹αž–αŸαž“αŸ’αž’αž“αžΉαž„αž€αžΆαžšαž‡αŸ’αžšαžΎαžŸαžšαžΎαžŸαž–αžΈαžŸαŸ†αžŽαž»αŸ†αž€αžΌαžŠαžŸαž˜αŸ’αž„αžΆαžαŸ‹ αž“αž·αž„αž–αž·αž’αžΈαž€αžΆαžšαžŠαŸαž‘αžΌαž›αŸ†αž‘αžΌαž›αžΆαž™ αžŠαŸ‚αž›αž–αž·αž”αžΆαž€αž™αž›αŸ‹αžŽαžΆαžŸαŸ‹αŸ” αžœαžΆαž˜αž·αž“αžαŸ‚αž„αžαŸ‚αž…αŸ’αž”αžΆαžŸαŸ‹αžαžΆαžˆαž»αžαžŸαž˜αŸ’αž„αžΆαžαŸ‹ αž“αž·αž„αž–αž·αž’αžΈαž€αžΆαžšαžŽαžΆαž˜αž½αž™αžαŸ’αžšαžΌαžœαž”αžΆαž“αž…αžΆαžαŸ‹αž‘αž»αž€αžαžΆ "αž˜αžΆαž“αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαžΆαž“αŸ‹" αž“αŸ„αŸ‡αž‘αŸαŸ”

αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžŠαŸ‚αž›αž”αžΆαž“αžŽαŸ‚αž“αžΆαŸ†

αž˜αž·αž“αž˜αžΆαž“αž“αžšαžŽαžΆαž˜αŸ’αž“αžΆαž€αŸ‹αž”αžΆαž“αž™αž›αŸ‹αž–αŸ’αžšαž˜αž‡αžΆαž•αŸ’αž›αžΌαžœαž€αžΆαžš αž“αž·αž„αž™αž›αŸ‹αž–αŸ’αžšαž˜αž›αžΎαž”αž‰αŸ’αž‡αžΈαž“αŸƒαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹ HTTPS αžŠαŸ‚αž›αž”αžΆαž“αžŽαŸ‚αž“αžΆαŸ†αž‘αŸαŸ” αžŠαžΌαž…αŸ’αž“αŸαŸ‡ αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž”αž„αŸ’αž€αžΎαžαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ Mozilla SSL αž•αŸ’αžαž›αŸ‹αž“αžΌαžœαž‡αž˜αŸ’αžšαžΎαžŸαž“αŸƒαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž‡αžΆαž…αŸ’αžšαžΎαž“ αž’αžΆαžŸαŸ’αžšαŸαž™αž›αžΎαž€αž˜αŸ’αžšαž·αžαž“αŸƒαž€αžΆαžšαž€αžΆαžšαž–αžΆαžšαžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž€αžΆαžšαŸ” αž§αž‘αžΆαž αžšαžŽαŸ αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸαŸ‡αž‡αžΆαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžŠαŸ‚αž›αž”αžΆαž“αžŽαŸ‚αž“αžΆαŸ†αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ nginx 1.14.0αŸ–

αžšαž”αŸ€αž”αž‘αŸ†αž“αžΎαž”

αž’αžαž·αžαž·αž‡αž“αžŠαŸ‚αž›αž‚αžΆαŸ†αž‘αŸ’αžšαž…αžΆαžŸαŸ‹αž‡αžΆαž„αž‚αŸαŸ– Firefox 27, Chrome 30, IE 11 αž“αŸ…αž›αžΎ Windows 7, Edge, Opera 17, Safari 9, Android 5.0, αž“αž·αž„ Java 8

server {
listen 80 default_server;
listen [::]:80 default_server;

# Redirect all HTTP requests to HTTPS with a 301 Moved Permanently response.
return 301 https://$host$request_uri;
}

server {
listen 443 ssl http2;
listen [::]:443 ssl http2;

# certs sent to the client in SERVER HELLO are concatenated in ssl_certificate
ssl_certificate /path/to/signed_cert_plus_intermediates;
ssl_certificate_key /path/to/private_key;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:50m;
ssl_session_tickets off;


# modern configuration. tweak to your needs.
ssl_protocols TLSv1.2;
ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256';
ssl_prefer_server_ciphers on;

# HSTS (ngx_http_headers_module is required) (15768000 seconds = 6 months)
add_header Strict-Transport-Security max-age=15768000;

# OCSP Stapling ---
# fetch OCSP records from URL in ssl_certificate and cache them
ssl_stapling on;
ssl_stapling_verify on;

## verify chain of trust of OCSP response using Root CA and Intermediate certs
ssl_trusted_certificate /path/to/root_CA_cert_plus_intermediates;

resolver <IP DNS resolver>;

....
}

αž€αžΆαžšαž‚αžΆαŸ†αž‘αŸ’αžšαž˜αž’αŸ’αž™αž˜

αž’αžαž·αžαž·αž‡αž“αžŠαŸ‚αž›αž‚αžΆαŸ†αž‘αŸ’αžšαž…αžΆαžŸαŸ‹αž‡αžΆαž„αž‚αŸαŸ– Firefox 1, Chrome 1, IE 7, Opera 5, Safari 1, Windows XP IE8, Android 2.3, Java 7

server {
listen 80 default_server;
listen [::]:80 default_server;

# Redirect all HTTP requests to HTTPS with a 301 Moved Permanently response.
return 301 https://$host$request_uri;
}

server {
listen 443 ssl http2;
listen [::]:443 ssl http2;

# certs sent to the client in SERVER HELLO are concatenated in ssl_certificate
ssl_certificate /path/to/signed_cert_plus_intermediates;
ssl_certificate_key /path/to/private_key;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:50m;
ssl_session_tickets off;

# Diffie-Hellman parameter for DHE ciphersuites, recommended 2048 bits
ssl_dhparam /path/to/dhparam.pem;

# intermediate configuration. tweak to your needs.
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
ssl_prefer_server_ciphers on;

# HSTS (ngx_http_headers_module is required) (15768000 seconds = 6 months)
add_header Strict-Transport-Security max-age=15768000;

# OCSP Stapling ---
# fetch OCSP records from URL in ssl_certificate and cache them
ssl_stapling on;
ssl_stapling_verify on;

## verify chain of trust of OCSP response using Root CA and Intermediate certs
ssl_trusted_certificate /path/to/root_CA_cert_plus_intermediates;

resolver <IP DNS resolver>;

....
}

αž€αžΆαžšαž‚αžΆαŸ†αž‘αŸ’αžšαž…αžΆαžŸαŸ‹

αž’αžαž·αžαž·αž‡αž“αžŠαŸ‚αž›αž‚αžΆαŸ†αž‘αŸ’αžšαž…αžΆαžŸαŸ‹αž‡αžΆαž„αž‚αŸαŸ– Windows XP IE6, Java 6

server {
listen 80 default_server;
listen [::]:80 default_server;

# Redirect all HTTP requests to HTTPS with a 301 Moved Permanently response.
return 301 https://$host$request_uri;
}

server {
listen 443 ssl http2;
listen [::]:443 ssl http2;

# certs sent to the client in SERVER HELLO are concatenated in ssl_certificate
ssl_certificate /path/to/signed_cert_plus_intermediates;
ssl_certificate_key /path/to/private_key;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:50m;
ssl_session_tickets off;

# Diffie-Hellman parameter for DHE ciphersuites, recommended 2048 bits
ssl_dhparam /path/to/dhparam.pem;

# old configuration. tweak to your needs.
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:ECDHE-RSA-DES-CBC3-SHA:ECDHE-ECDSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:DES-CBC3-SHA:HIGH:SEED:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!RSAPSK:!aDH:!aECDH:!EDH-DSS-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA:!SRP';
ssl_prefer_server_ciphers on;

# HSTS (ngx_http_headers_module is required) (15768000 seconds = 6 months)
add_header Strict-Transport-Security max-age=15768000;

# OCSP Stapling ---
# fetch OCSP records from URL in ssl_certificate and cache them
ssl_stapling on;
ssl_stapling_verify on;

## verify chain of trust of OCSP response using Root CA and Intermediate certs
ssl_trusted_certificate /path/to/root_CA_cert_plus_intermediates;

resolver <IP DNS resolver>;

....
}

αžœαžΆαžαŸ’αžšαžΌαžœαž”αžΆαž“αžŽαŸ‚αž“αžΆαŸ†αžαžΆαž’αŸ’αž“αž€αžαŸ‚αž„αžαŸ‚αž”αŸ’αžšαžΎαžˆαž»αžαž’αž€αŸ’αžŸαžšαžŸαž˜αŸ’αž„αžΆαžαŸ‹αž–αŸαž‰αž›αŸαž‰ αž“αž·αž„αž€αŸ†αžŽαŸ‚αž…αž»αž„αž€αŸ’αžšαŸ„αž™αž”αŸ†αž•αž»αžαžšαž”αžŸαŸ‹ OpenSSL αŸ” ឈុត cipher αž“αŸ…αž€αŸ’αž“αž»αž„αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ αž”αž‰αŸ’αž‡αžΆαž€αŸ‹αž–αžΈαž’αžΆαž‘αž·αž—αžΆαž–αžŠαŸ‚αž›αž–αž½αž€αžœαžΆαž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αŸ’αžšαžΎ αž’αžΆαžŸαŸ’αžšαŸαž™αž›αžΎαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž—αŸ’αž‰αŸ€αžœαŸ”

αž€αžΆαžšαžŸαŸ’αžšαžΆαžœαž‡αŸ’αžšαžΆαžœαž”αž„αŸ’αž αžΆαž‰αžαžΆαžœαžΆαž˜αž·αž“αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαžΆαž“αŸ‹αžŠαžΎαž˜αŸ’αž”αžΈαžŠαŸ†αž‘αžΎαž„αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžš HTTPS αž‘αŸαŸ” "αžαžŽαŸˆαž–αŸαž›αžŠαŸ‚αž›αž™αžΎαž„αž˜αž·αž“αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„αžαžΌαžƒαžΈαžŠαžΌαž…αžŠαŸ‚αž›αž™αžΎαž„αž”αžΆαž“αž’αŸ’αžœαžΎαž€αŸ’αž“αž»αž„αž†αŸ’αž“αžΆαŸ† 2005 αž αžΎαž™ ' TLS αžŸαž˜αžšαž˜αŸ’αž™' αž”αžΆαž“αž€αŸ’αž›αžΆαž™αž‡αžΆαžšαžΏαž„αž’αž˜αŸ’αž˜αžαžΆ αžœαžΆαž”αž„αŸ’αž αžΆαž‰αžαžΆαžšαžΏαž„αž‡αžΆαž˜αžΌαž›αžŠαŸ’αž‹αžΆαž“αž‘αžΆαŸ†αž„αž“αŸαŸ‡αž˜αž·αž“αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαžΆαž“αŸ‹αžŠαžΎαž˜αŸ’αž”αžΈαž’αžΆαž“αžΆαž”αžΆαž“αž“αžΌαžœαž…αŸ†αž“αž½αž“αžŠαŸαž…αŸ’αžšαžΎαž“αž‚αž½αžšαž±αŸ’αž™αž—αŸ’αž‰αžΆαž€αŸ‹αž•αŸ’αž’αžΎαž›αž“αŸƒαž‚αŸαž αž‘αŸ†αž–αŸαžšαž–αŸαž‰αž“αž·αž™αž˜αžαŸ’αž›αžΆαŸ†αž„" αž“αž·αž™αžΆαž™ αž’αŸ’αž“αž€αž“αž·αž–αž“αŸ’αž’αž“αŸƒαž€αžΆαžšαž„αžΆαžšαŸ” αžŠαžΎαž˜αŸ’αž”αžΈαž€αžΆαžšαž–αžΆαžšαž”αŸ‰αž»αžŸαŸ’αžαž·αŸαžšαžœαžΆαž„αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ αž“αž·αž„αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž—αŸ’αž‰αŸ€αžœαž”αŸ’αžšαž€αž”αžŠαŸ„αž™αž—αžΆαž–αž‡αžΏαž‡αžΆαž€αŸ‹ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαžαŸ’αžšαž½αžαž–αž·αž“αž·αžαŸ’αž™αžŠαŸ„αž™αž”αŸ’αžšαž»αž„αž”αŸ’αžšαž™αŸαžαŸ’αž“αž“αžΌαžœαž αŸαžŠαŸ’αž‹αžΆαžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž–αžΈαžŠαŸ‚αž“αžšαž„αž•αŸ’αž‘αžΆαž›αŸ‹αžαŸ’αž›αž½αž“αžšαž”αžŸαŸ‹αž’αŸ’αž“αž€ αž“αž·αž„αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž—αžΆαž‚αžΈαž‘αžΈαž”αžΈαž–αžΈαž˜αžΆαžαž·αž€αžΆαžŽαžΆαž˜αž½αž™αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž‚αŸαž αž‘αŸ†αž–αŸαžšαžαŸ’αžšαžΌαžœαž”αžΆαž“αž•αŸ’αž‚αžαŸ‹αž•αŸ’αž‚αž„αŸ‹αŸ” αž”αŸ’αžšαž αŸ‚αž›αž‡αžΆαžœαžΆαžŸαž˜αž αŸαžαž»αž•αž›αž€αŸ’αž“αž»αž„αž€αžΆαžšαž”αž‰αŸ’αž‡αžΆαž‘αž·αž‰αžŸαžœαž“αž€αž˜αŸ’αž˜αž–αžΈαž€αŸ’αžšαž»αž˜αž αŸŠαž»αž“αž—αžΆαž‚αžΈαž‘αžΈαž”αžΈαž˜αž½αž™αž…αŸ†αž“αž½αž“αžŠαŸ‚αž›αž˜αžΆαž“αž―αž€αž‘αŸαžŸαžαžΆαž„αžŸαž“αŸ’αžαž·αžŸαž»αžαž–αŸαžαŸŒαž˜αžΆαž“αŸ”

HTTPS αž˜αž·αž“αžαŸ‚αž„αžαŸ‚αž˜αžΆαž“αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αžŠαžΌαž…αžŠαŸ‚αž›αžœαžΆαž αžΆαž€αŸ‹αžŠαžΌαž…αž‡αžΆαž“αŸ„αŸ‡αž‘αŸαŸ” αž—αžΆαž–αž„αžΆαž™αžšαž„αž‚αŸ’αžšαŸ„αŸ‡αžαŸ’αžšαžΌαžœαž”αžΆαž“αžšαž€αžƒαžΎαž‰αž“αŸ…αž€αŸ’αž“αž»αž„ 5,5% αž“αŸƒαž‚αŸαž αž‘αŸ†αž–αŸαžš HTTPS

αž”αŸ’αžšαž—αž–: www.habr.com