Get an A+ grade on SSL Labs

You installed SSL but SSL Labs only gives you a B or C? A good score doesn't come from simply having a certificate — it comes from a correct TLS configuration. This guide walks you through each step until your site earns an A+ on SSL Labs.

What is an SSL Labs A+ grade

SSL Labs (Qualys) is a free tool that scans your server's SSL/TLS configuration and grades it from F to A+. A+ is the highest score, requiring you to pass checks on protocols, ciphers, and key exchange, and to enable HSTS correctly. An A+ signals that your site encrypts connections securely to the latest standards.

What SSL Labs scores you on

A common misconception is that simply installing a valid certificate is enough. In reality SSL Labs evaluates four core categories and then uses the weakest one to cap your grade. That means a single weak area drags the whole score down, no matter how strong the others are. Understanding where the weighting falls lets you fix the right things rather than guessing.

The categories the engine grades are:

Once all four categories reach A level, earning the "A+" is a separate bonus that requires enabling HSTS. This is the dividing line between A and A+ that many sites overlook.

Checklist for an A+

Before you run a real scan, work through this checklist item by item. If every box is ticked, your odds of an A+ are very high. The table below summarizes what to do and why:

Item Required state Why it matters
Disable TLS 1.0 / 1.1 Both off Legacy protocols are deprecated and vulnerable; they cap your score
Enable TLS 1.3 On (with TLS 1.2) Fastest and most secure; full protocol score
Strong ciphers AES-GCM only Drop weak RC4/3DES/CBC to avoid losing points
Forward Secrecy ECDHE Past traffic stays safe even if a key leaks later
HSTS max-age ≥ 6 months Mandatory condition to move from A to A+
OCSP Stapling On Speeds up cert status checks, cuts handshake latency

Step 1 — Disable old protocols

Enable only TLS 1.2 and TLS 1.3, and disable SSLv3, TLS 1.0 and TLS 1.1. On Apache (mod_ssl):

SSLProtocol -all +TLSv1.2 +TLSv1.3

On Nginx:

ssl_protocols TLSv1.2 TLSv1.3;

Step 2 — Choose strong cipher suites

Use Forward Secrecy ciphers (ECDHE) and disable weak ones like RC4 and 3DES. On Nginx:

ssl_prefer_server_ciphers on; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;

Step 3 — Enable HSTS (the key to A+)

Add this header to force browsers to always use HTTPS — this is what separates an A from an A+:

Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"

Once ready you can register on the HSTS Preload List at hstspreload.org.

Step 4 — OCSP Stapling and DH params

Enable OCSP Stapling to speed up certificate status checks, and use a Diffie-Hellman key of 2048 bits or more. On Nginx:

ssl_stapling on; ssl_stapling_verify on;

Caution: Before enabling HSTS preload, make sure every subdomain supports HTTPS, because once preloaded it is difficult and slow to remove.

Example config to enable TLS 1.3 + HSTS (Nginx / Apache)

To see how every step comes together, here is a complete configuration that enables TLS 1.2/1.3 with strong ciphers, HSTS, and OCSP stapling in one place — ready to adapt to your server.

Nginx (inside the server { ... } block listening on 443):

ssl_protocols TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384; ssl_session_cache shared:SSL:10m; ssl_session_timeout 1d; ssl_stapling on; ssl_stapling_verify on; add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;

Apache (inside <VirtualHost *:443> or your ssl.conf):

SSLProtocol -all +TLSv1.2 +TLSv1.3 SSLHonorCipherOrder on SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384 SSLUseStapling on SSLStaplingCache "shmcb:logs/ssl_stapling(32768)" Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"

After editing the config, always test the syntax before reloading so you don't take the server down: Nginx uses nginx -t then systemctl reload nginx, while Apache uses apachectl configtest then systemctl reload apache2 (or httpd on some distributions).

Things to check before enabling HSTS preload

HSTS preload is a double-edged sword. It forces browsers to always use HTTPS for your domain — baked right into the browser — without waiting for the first header, which is very secure but hard to reverse. Before submitting to hstspreload.org, verify all of the following:

  1. Every subdomain (including ones you haven't used yet) must support HTTPS, because includeSubDomains covers all of them — if any subdomain is still HTTP-only, users won't be able to reach it at all.
  2. Certificates for the apex domain and every subdomain must renew automatically; otherwise once a certificate expires there is no way for users to bypass the warning.
  3. Start with a short max-age (a few hours), then raise it to one year once you're confident, and only then add preload as the final step.
  4. Removal from the preload list can take many months to propagate across all browsers, so don't rush to preload until you're 100% ready.

In short, a plain HSTS header is already enough for an A+. Submitting to the preload list is an extra step reserved for sites certain they will use HTTPS forever.

Verify with SSL Labs

After configuring, go to ssllabs.com/ssltest, enter your domain and wait for the result. If you're not at A+ yet, the report tells you exactly what's holding you back — old protocols still enabled, or missing HSTS. Fix what it flags and rescan.

One small gotcha trips up a lot of people: SSL Labs caches your most recent scan. If you've just changed the config and rescan immediately, you may still see the old result. Tick the "Clear cache" option or append &clearCache=on to the URL to force a fresh scan. Also remember to reload or restart the web service after every config change, otherwise the new values aren't actually live on the server yet.

Another point that's often overlooked: if your site sits behind a CDN or reverse proxy (such as Cloudflare), the TLS configuration end users see belongs to the edge, not your origin server. So if you use a CDN, you must tune TLS/HSTS on the CDN side too — otherwise no matter how perfectly you configure the origin, the grade SSL Labs reports is still the edge's.

Keeping your A+ over time

Earning an A+ the first time is only the start, because security standards keep shifting. A cipher considered strong today may be downgraded a few years from now, and new protocols keep arriving. Maintaining the grade means rechecking periodically — set a reminder to scan SSL Labs every 3-6 months, or any time you upgrade the server.

The things that most often drop the grade are few: a certificate nearing expiry that you forget to renew, a web server update that resets your cipher settings back to defaults, and adding a new subdomain without SSL while HSTS includeSubDomains is already on. Setting up automatic certificate renewal and documenting your tuned config keeps your site at A+ sustainably, without scrambling to fix it from scratch each time.

Frequently asked questions

What is an SSL Labs A+ grade?

An A+ is the top score from SSL Labs (Qualys), which evaluates a server's SSL/TLS configuration. To earn A+ a site must disable old protocols, allow only TLS 1.2/1.3, use strong ciphers, and enable HSTS correctly.

Do I really need to disable TLS 1.0 and 1.1?

Yes. TLS 1.0/1.1 are deprecated and have known weaknesses. Leaving them on lowers your score and exposes you to attacks. Enable only TLS 1.2 and 1.3.

Is HSTS required for an A+ grade?

Yes. Earning A+ (rather than A) requires enabling HTTP Strict Transport Security via the Strict-Transport-Security header with a max-age of at least six months, forcing browsers to always use HTTPS.

Can a free Let's Encrypt certificate reach A+?

Yes. The A+ grade depends on your server's TLS configuration, not on whether the certificate is free or paid. Let's Encrypt certificates use the same standard keys and chain. As long as you disable old protocols, use strong ciphers, and enable HSTS correctly, a free certificate earns an A+ just the same.

SSL Certificates you can configure to A+

AsiaGB offers SSL from RapidSSL and DigiCert with setup guidance, starting at ฿1,000/year.

View SSL Plans