# Request: Recommended Server Configurations

**URL:** <https://community.letsencrypt.org/t/request-recommended-server-configurations/25977>\
**Category:** Feature Requests\
**Created:** [January 18, 2017, 6:23pm UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977 "2017-01-18T18:23:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jvanasco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jvanasco/32/55900_2.png) [@jvanasco](https://community.letsencrypt.org/u/jvanasco)\
**Post date:** [January 18, 2017, 6:23pm UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977/1 "2017-01-18T18:23:05Z")

</div>

Reposting this as it was never addressed and now locked:

It would be great if the .org, docs, or this site kept an (updated) recommended configuration file for various web servers (e.g. which protocols/etc should be enabled). This could probably mirror what certbot is automating, but surfacing it in a way that people using ‘certonly’ or those interested in the configuration specifics can reference.

---

<div class="post-metadata">

**Author:** ![TCM](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@TCM](https://community.letsencrypt.org/u/TCM)\
**Post date:** [January 18, 2017, 6:46pm UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977/2 "2017-01-18T18:46:40Z")

</div>

If certbot already does this, interested parties should just look at the source or documentation there.

Tracking identical data in multiple places rarely works long-term.

---

<div class="post-metadata">

**Author:** ![jvanasco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jvanasco/32/55900_2.png) [@jvanasco](https://community.letsencrypt.org/u/jvanasco)\
**Post date:** [January 18, 2017, 7:02pm UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977/3 "2017-01-18T19:02:46Z")

</div>

That requires someone to have a working knowledge of Python – which certbot is written in and not guaranteed to the target audience of end-users.

A large number of posts in this forum, and on StackOverflow, have to do with people asking for information like this.

The information could be centrally tracked/managed (within certbot, elsewhere?) and exposed in a readable format to end-users as part of build scripts.

---

<div class="post-metadata">

**Author:** ![motoko](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/motoko/32/26328_2.png) [@motoko](https://community.letsencrypt.org/u/motoko)\
**Post date:** [January 18, 2017, 7:36pm UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977/4 "2017-01-18T19:36:57Z")

</div>

Configuration at this level is often specialized to the environment. I don’t see that Let’s Encrypt could provide a solid job at this type of thing.

I personally recommend looking at [https://mozilla.github.io/server-side-tls/ssl-config-generator/](https://mozilla.github.io/server-side-tls/ssl-config-generator/) if you want a good starting point for best-practice configuration of encryption ciphers, protocols, etc.

If you’re using IIS, I personally recommend using [https://www.nartac.com/Products/IISCrypto/](https://www.nartac.com/Products/IISCrypto/) for configuration there.

---

<div class="post-metadata">

**Author:** ![jvanasco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jvanasco/32/55900_2.png) [@jvanasco](https://community.letsencrypt.org/u/jvanasco)\
**Post date:** [February 10, 2017, 11:53pm UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977/5 "2017-02-10T23:53:28Z")

</div>

letsencrypt could do a stellar job at this, as they already do. certbot does this for the automatic installs (via apache/nginx).

i’m talking about printing what the plugin does (ie recommended) into the docs.

---

<div class="post-metadata">

**Author:** ![motoko](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/motoko/32/26328_2.png) [@motoko](https://community.letsencrypt.org/u/motoko)\
**Post date:** [February 11, 2017, 5:56am UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977/6 "2017-02-11T05:56:20Z")

</div>

Based on the code, it looks like they’re using the “intermediate” configuration from the Mozilla config generator for Apache HTTPd.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 13, 2017, 5:56am UTC](https://community.letsencrypt.org/t/request-recommended-server-configurations/25977/7 "2017-03-13T05:56:49Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
