Netsparker detected that insecure transportation security protocol (TLS 1.0) is supported by your web server.
TLS 1.0 has several flaws. An attacker can cause connection failures and they can trigger the use of TLS 1.0 to exploit vulnerabilities like BEAST (Browser Exploit Against SSL/TLS).
Websites using TLS 1.0 will be considered non-compliant by PCI after 30 June 2018.
Configure your web server to disallow using weak ciphers. You need to restart the web server to enable changes.
SSLProtocol +TLSv1.1 +TLSv1.2
nginx.conffile and remove
ssl_protocols TLSv1.1 TLSv1.2;
regedit, and then click OK.
Serveror create if it doesn't exist.
Serverkey, locate a DWORD value named
Enabledor create if it doesn't exist and set its value to "0".