πŸ”’
SSL & TLS

Configuring Cipher Suites for Optimal Security

πŸ“… 11 October 2026 ✏️ 11 October 2026 ⏱ 5 min leestijd

Learn how to properly configure cipher suites for a secure SSL/TLS connection, better security, and a high internet.nl score.

A cipher suite determines which encryption methods your server uses to encrypt data between the server and visitor. An incorrect or outdated configuration makes your website vulnerable, even with a valid SSL certificate. In this article, you’ll learn which cipher suites you should and shouldn’t use, how to set them up via Plesk or your server configuration, and how to test the settings.

What are cipher suites and why are they important

A cipher suite is a combination of algorithms that together determine how a TLS connection is established: the key exchange algorithm, the encryption algorithm, and the hash algorithm for integrity checking. When a browser connects to your server, both parties negotiate which cipher suite to use. If your server still allows outdated cipher suites, you risk attacks such as BEAST, POODLE, or downgrade attacks, even if you have a valid certificate installed.

Well-configured cipher suites also affect assessments such as the internet.nl score, which is increasingly used by governments and businesses to evaluate the security of websites and email services.

Which cipher suites should you use

A number of rules of thumb apply for a modern, secure configuration:

  • Only use TLS 1.2 and TLS 1.3; completely disable SSLv3, TLS 1.0, and TLS 1.1.
  • Choose cipher suites with forward secrecy (ECDHE or DHE key exchange), so that previously intercepted sessions cannot be decrypted later if a key is leaked.
  • Avoid RC4, DES, 3DES, and export cipher suites; these are outdated and insecure.
  • Prefer AES-GCM over CBC modes, since GCM is resistant to certain padding attacks.
  • With TLS 1.3, let the server configuration do the heavy lifting; this protocol no longer allows weak suites by default.
πŸ’‘ Tip: Always test after every change to ensure your website remains accessible for visitors with older browsers, especially if you completely disable older protocols.

Configuring cipher suites

How you configure cipher suites depends on your server stack. On servers with Apache or Nginx, you usually adjust this in the SSL configuration; on a LiteSpeed server, this can be done via the web server panel or the configuration files.

1

Check the current configuration

Review which protocols and cipher suites are currently active, for example via the SSL/TLS settings in Plesk or by opening your web server’s configuration file.

2

Disable outdated protocols

Turn off SSLv3, TLS 1.0, and TLS 1.1 in the configuration. Keep only TLS 1.2 and TLS 1.3 active.

3

Set up a modern cipher list

Add a cipher string that only includes ECDHE- and AES-GCM-based suites, and remove weak or outdated options from the list.

4

Restart the web server

Restart Apache, Nginx, or LiteSpeed so the new configuration is loaded, and check whether the site still loads normally.

5

Check email traffic

If relevant, also adjust the TLS settings of your mail server, so that sending and receiving email remains encrypted according to current guidelines.

In Plesk, you’ll find most SSL/TLS settings clearly organized under the domain settings, which makes adjusting protocols and cipher preferences easier than working manually in configuration files. If you don’t manage your own server but use web hosting, this configuration is usually already maintained for you.

BrowserTLS negotiationcipher suite selectionServer

Testing and verifying your configuration

After adjusting your cipher suites, it’s important to verify that the changes have been correctly implemented and that no unintended problems arise. Use an external SSL test to see which protocols and cipher suites your server still offers, and check whether outdated options have actually been removed. Also test whether your website and any business email still function properly on various devices and browsers.

If you get stuck while adjusting your configuration, consult the knowledge base for more background information or contact your hosting provider. If you’re considering switching because your current provider doesn’t support modern TLS settings, check out the options to switch to Tandata.

Frequently Asked Questions

What happens if I set overly strict cipher suites?

Visitors with very old browsers or operating systems may no longer be able to connect to your website. Strike a balance between security and compatibility, depending on your target audience.

Should I always disable TLS 1.0 and 1.1?

In most cases, yes, since these protocols are considered outdated and insecure. Only if you can demonstrate that you still have visitors who can only connect using these should you reconsider.

Does the cipher suite also affect my email security?

Yes, mail servers also use TLS for encrypted connections. A good cipher suite configuration contributes to a higher security score for both your website and email.

How often should I check my cipher suites?

Check your configuration periodically, and certainly after major updates to your server or web server software, since security insights and recommendations regularly change.

Can I set this up myself without technical knowledge?

With a control panel like Plesk, this is easier than manual configuration, but if in doubt, it’s wise to have this checked by an experienced administrator.

Conclusion

Correctly configured cipher suites are essential for a secure TLS connection. Use only TLS 1.2 and 1.3, choose cipher suites with forward secrecy and AES-GCM, and test your configuration regularly. This protects both your website and your email traffic against outdated and insecure connections.

View web hosting β†’

Was dit artikel nuttig?