Jump to content

I'm using LetsEncryp's SSL certificate for my webserver. When I look at the certificate on Chrome it tells me I'm using Obsolete Cipher. The odd thing is if I check the SSL certifce on ssllabs.com the rating is good? Domain website is: www.learntotech.co.uk

 

 

 

Spoiler

 

 

 

bea7666a186c93deda5464d8c6785dc8.png

 

 

8d1c68396a5e18e8e81c436942a5b7e6.png

 

 

 

 

 

 

 

 

 

 

 

 

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/
Share on other sites

Link to post
Share on other sites

Just now, Lurick said:

You need to switch over to SHA2 from SHA1

How do I do that on Windows 2012? Do you know? 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416482
Share on other sites

Link to post
Share on other sites

2 minutes ago, Lurick said:

You need to switch over to SHA2 from SHA1

 

Edit:

Also, you blanked out the domain name but left the public IP :P 

I fixed it. :P 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416488
Share on other sites

Link to post
Share on other sites

Current Network Layout:

Current Build Log/PC:

Storage Server Setup:

 

Prior Build Log/PC:

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416495
Share on other sites

Link to post
Share on other sites

3 minutes ago, Lurick said:

You need to switch over to SHA2 from SHA1

 

Edit:

Also, you blanked out the domain name but left the public IP :P 

I mean I hid the IP address. Not fixed yet. :( 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416498
Share on other sites

Link to post
Share on other sites

As far as I can see, by "obsolete cipher", they just mean that it's not using AES-GCM, which I think is only supported in the most recent browsers. It's not a security problem, though the GCM cipher does what previously required two things (a different form of AES + SHA1). There's no urgent need to switch, and I don't know that it's even possible with many servers at the moment.

Your certificate is using SHA-256, and if it wasn't you would be getting much more prominent security warnings.

(You also left your domain in the breadcrumbs, but having the domain does make it easier to debug)

HTTP/2 203

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416509
Share on other sites

Link to post
Share on other sites

2 minutes ago, colonel_mortis said:

(You also left your domain in the breadcrumbs, but having the domain does make it easier to debug)

Well I Hid it. Not allowed to show my personal website or the domain on here? 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416523
Share on other sites

Link to post
Share on other sites

Just now, Abdul201588 said:

Well I Hid it. Not allowed to show my personal website or the domain on here? 

Provided that you're not posting it to advertise your site, it's ok to include the domain in the screenshot to allow people to debug it.

HTTP/2 203

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416527
Share on other sites

Link to post
Share on other sites

Just now, colonel_mortis said:

Provided that you're not posting it to advertise your site, it's ok to include the domain in the screenshot to allow people to debug it.

okay! :D The domain is www.learntotech.co.uk. I'll edit my post. 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416531
Share on other sites

Link to post
Share on other sites

Might want to change the site to redirect to the HTTPS version, when I go to it without the www in front then I get the IIS Windows page.

Current Network Layout:

Current Build Log/PC:

Storage Server Setup:

 

Prior Build Log/PC:

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416546
Share on other sites

Link to post
Share on other sites

Just now, Lurick said:

Might want to change the site to redirect to the HTTPS version, when I go to it without the www in front then I get the IIS Windows page.

I've edited. I've put in www. It does redirect from HTTP to HTTPS. :) 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416553
Share on other sites

Link to post
Share on other sites

Just now, Abdul201588 said:

I've edited. I've put in www. It does redirect from HTTP to HTTPS. :) 

I know but without it I'm getting the IIS page, you'll want to fix that so people don't have to put in the www.

Current Network Layout:

Current Build Log/PC:

Storage Server Setup:

 

Prior Build Log/PC:

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416557
Share on other sites

Link to post
Share on other sites

4 minutes ago, Lurick said:

I know but without it I'm getting the IIS page, you'll want to fix that so people don't have to put in the www.

Will do. 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/833279-obsolete-cipher/#findComment-10416573
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×