sslscan
sslscan copied to clipboard
TLS1.2 only and missing SCSV
I'm not 100% sure about this issue but I assumed it may be worth discussing.
If a web server allows only TLS 1.2 but also does not support SCSV,
does SSLScan flag that as bad practice/bad configuration?
Because if so, I do not see the reason why to do that - or am I missing something?