The ultimate resource hub for optimal SSL/TLS deployment
Welcome to our SSL/TLS Best Practices Resource hub, where you’ll find everything you need for the latest in optimizing your SSL/TLS configurations. Here you’ll be able to
- browse our expert configuration guides for specific best practices,
- see the latest configuration stats from the web, and
- find links and videos to other best practices guides.
If this is your first time here or were just looking for a full list of best practices, make sure to download our FREE SSL/TLS Best Practices Checklist (below).
Download the Best Practices Checklist
Are you checking the boxes?
Take a Look at Our Expert Guides
Read deep-dives on specific SSL/TLS best practices.
Review Industry SSL/TLS Statistics
How well does the internet implement SSL/TLS best practices? Find out.
Basic Configuration Guides by Server Type
SSL/TLS Configuration Guides
-

What Is HSTS Preload? How to Check & Enable It
HTTP strict transport security (HSTS) preload (also called HSTS preloading) ensures that browsers always connect to your website securely via the hypertext transfer protocol (HTTPS). It preloads your domain into…
-

What Is OCSP Stapling and How Does It Work?
OCSP stapling is a performance-enhancing and privacy-protecting extension to the online certificate status protocol (OCSP). Basically, its job is to streamline validating an SSL/TLS certificate’s revocation status. Without OCSP stapling, browsers…
-

Do I Need a CAA Record? How to Check & Add One
A certificate authority authorization (CAA) record is a DNS resource that boosts security by giving site owners control over which certification authorities (CAs) can issue SSL/TLS certificates for their domains.…
-

How to Configure OCSP Stapling on an Apache HTTP Server
OCSP stapling improves SSL/TLS performance by making your Apache web server attach (i.e., “staple”) its certificate’s status information to the TLS handshake. This prevents clients from sending additional requests to…
SSL/TLS Configuration Statistics
When you visit a website that displays the padlock, you might assume it’s secure. But how many of those sites have actually configured secure encryption? How many websites follow basic SSL/TLS best practices? We took the top 100 websites (by traffic) and compared their SSL/TLS configurations to a random cross-section sites across the web. See how they stack up:
| SSL/TLS Best Practice | Top 100 websites | Random Cross-section |
|---|---|---|
| Disabled SSL V2 | 100% | 99.82% |
| Disabled SSL V3 | 99% | 98.42% |
| Has TLS 1 | 40% | 23.47% |
| Has TLS 1.1 | 41% | 25.04% |
| Has TLS 1.2 | 100% | 60.42% |
| Has TLS 1.3 | 86% | 60.77% |
| HSTS Offered | 55% | 16.81% |
| HSTS Preload Enabled | 30% | 0.09% |
| Has CAA Record | N/A | 4.38% |
| Has OCSP Stapling | N/A | 35.55% |
| http redirects to https | 71% | 76.97% |
| Has Intermediate Certificate | N/A | 72.24% |
Data collected April 2025, based on analysis of websites on the Tranco List.
SSL/TLS Deployment Best Practices Course
Learn the basic components of SSL/TLS configuration by Ivan Ristić, the author of SSL Labs. Taken from his book Bulletproof SSL and TLS, the following video covers the configuration best practices of Keys, Certificates, Protocols, Suites, and more!
Video Contents:
- Keys: Algorithms, Size, & Management
- Certificates: Validation, Hostnames, Sharing, Lifetime, Signature Algorithms, & Chain Correctness
- Protocol Configuration
- SSL Pulse: Protocol Support, Forward Secrecy
- Suites: Configuration, Compatibility, & New Suites Coming Soon



