Plesk SSL Hardening Guide: Enforcing TLS 1.3, Modern Cipher Suites, HSTS, and HTTP/2 on Pakistani Servers

Master SSL/TLS hardening in Plesk Obsidian. Learn how to eliminate weak ciphers (CBC, 3DES), configure Mozilla Modern TLS 1.3 parameters, enable HSTS with preloading, and achieve an A+ rating on Qualys SSL Labs.

Plesk SSL Hardening Guide: Enforcing TLS 1.3, Modern Cipher Suites, HSTS, and HTTP/2 on Pakistani Servers

Plesk Obsidian is one of the most capable control panels for hosting multi-tenant WordPress, Node.js, and Docker applications on Dedicated Servers. Through the SSL It! extension, Plesk makes obtaining Let’s Encrypt certificates seamless with a single click.

However, obtaining an SSL certificate is only the first step. By default, Plesk’s global web server templates (Nginx and Apache) maintain backward compatibility with older TLS 1.2 handshakes and legacy cipher suites. This leaves sites vulnerable to cryptographic downgrade attacks, CBC padding issues, and lower security scores on compliance audits like PCI-DSS and Qualys SSL Labs.

In this guide, we dive deep into hardening Plesk’s cryptographic profile: enforcing TLS 1.3, adopting modern elliptic-curve ciphers, enabling HTTP Strict Transport Security (HSTS) with preloading, and tuning OCSP stapling for optimal handshake latency.


The Anatomy of Modern TLS 1.3 Handshakes

Legacy TLS versions (1.0, 1.1, and basic 1.2) require two round trips (2-RTT) between the browser and server to negotiate cipher suites, exchange keys, and verify certificate chains. In contrast, TLS 1.3 reduces this to a single round trip (1-RTT), or zero round trips (0-RTT) for returning sessions.

Client (Browser)                                    Plesk Server (Nginx)
       │                                                     │
       ├──── ClientHello + Key Share + Supported Groups ────►│ (1-RTT)
       │                                                     │
       │◄─── ServerHello + Key Share + Finished ─────────────┤
       │                                                     │
  [Encrypted Application Data Flow Commences Instantly]

Beyond speed, TLS 1.3 deprecates all unsafe cryptographic primitives, including:

  • RSA key exchange (Forward Secrecy is now mandatory via ECDHE).
  • CBC mode ciphers (eliminates Lucky Thirteen and POODLE attacks).
  • Weak hashing algorithms like MD5 and SHA-1.

Method 1: Global TLS Hardening via Plesk CLI (plesk sbin sslmng)

The safest and most resilient way to enforce modern SSL configurations across all hosted domains in Plesk is via Plesk’s native SSL management CLI. This ensures your settings are preserved across Plesk Obsidian system updates.

Connect to your Plesk server via SSH as root:

# 1. Inspect current server-wide SSL protocols
plesk bin server_pref --show-tls-protocols

Enforce Modern Protocols (TLS 1.2 & TLS 1.3 Only)

Disable deprecated TLS 1.0 and TLS 1.1 protocols system-wide:

# Set global supported protocols
plesk bin server_pref --set-tls-protocols "TLSv1.2 TLSv1.3"

Configure Mozilla Intermediate / Modern Cipher Suite

To ensure compatibility with modern clients while barring obsolete ciphers:

# Apply hardened cipher list for Nginx and Apache
plesk bin server_pref --set-tls-ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384"

Method 2: Customizing Nginx Directives for A+ Rating

In Plesk Obsidian, Nginx acts as the high-performance reverse proxy sitting in front of Apache or PHP-FPM. You can inject custom SSL directives globally or on a per-domain basis.

Navigate to Domains > yourdomain.pk > Apache & nginx Settings > Additional nginx directives, and add:

# Enforce SSL Session Cache and Tickets for Fast Handshakes
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;

# Diffie-Hellman Parameter for DHE Ciphers (Generated with 2048 or 4096 bits)
# Generated via: openssl dhparam -out /etc/nginx/dhparam.pem 2048
ssl_dhparam /etc/nginx/dhparam.pem;

# OCSP Stapling: Eliminates client certificate revocation latency
ssl_stapling on;
ssl_stapling_verify on;
resolver 1.1.1.1 8.8.8.8 valid=300s;
resolver_timeout 5s;

# HTTP Strict Transport Security (HSTS) with Subdomains and Preload
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;

# Prevent Clickjacking & MIME-type Sniffing
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;

Step 3: Enabling OCSP Stapling in the Plesk GUI

If you prefer managing SSL settings through the visual dashboard:

  1. Go to Extensions > SSL It!.
  2. Click on the domain you want to harden.
  3. Check Keep websites secured and toggle HSTS to On.
  4. Set the Max-Age to at least 6 months (15768000 seconds).
  5. Check Include subdomains and Preload.
  6. Check Turn on OCSP Stapling.

Step 4: Testing & Verifying Your SSL Configuration

Once you apply your updates, restart the web services to activate changes:

# Gracefully reload Nginx and Apache in Plesk
systemctl reload nginx
systemctl reload httpd # or systemctl reload apache2 on Ubuntu

Local CLI Verification via OpenSSL

Test that deprecated TLS 1.0 and 1.1 handshakes are actively refused:

# This test MUST fail with a handshake failure
openssl s_client -connect yourdomain.pk:443 -tls1_1

Expected output:

CONNECTED(00000003)
write:errno=104
---
no peer certificate available
---
No client certificate CA names sent

Test TLS 1.3 connectivity:

openssl s_client -connect yourdomain.pk:443 -tls1_3

Expected output:

New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 256 bit EC (or 2048 bit RSA)
Secure Renegotiation IS NOT supported (TLS 1.3 native)

With TLS 1.3 enforced, HSTS headers active, and OCSP stapling configured, testing your domain on Qualys SSL Labs will yield a flawless A+ Grade.

High-Security Bare Metal

Enterprise Plesk & cPanel Dedicated Servers in Pakistan

Deliver ultra-fast, encrypted web experiences to your customers. NextGen Dedicated Servers feature enterprise hardware firewalls, native BGP routing, and automated Plesk Obsidian provisioning.