SSL / HTTPS / TLS Certificate Settings
All sites are automatically issued an SSL/TLS certificate as part of setup, and certificates are renewed for you. This encrypts communications between visitors and your site over HTTPS, with HTTPS enforced for all traffic.
The WAF serves TLS 1.2 and TLS 1.3 with a modern cipher suite selection, chosen to work well with Heroku and to satisfy current compliance baselines (PCI DSS requires TLS 1.2 or higher). Legacy protocols such as TLS 1.0 and 1.1 are disabled at the edge. There is nothing to configure.
For the full protocol and cipher suite details, including how to test your site’s TLS configuration, see TLS Versions and Cipher Suites.
Need Help?
- Contact us at support@expeditedsecurity.com
- Book a Call at https://app.harmonizely.com/expedited/30-min