SSL/TLS Forward Secrecy Support for Custom Domains?

164 views
Skip to first unread message

Thomas Schranz

unread,
Jun 26, 2013, 7:31:02 PM6/26/13
to google-a...@googlegroups.com

Thomas Schranz

unread,
Jul 4, 2013, 3:08:43 PM7/4/13
to google-a...@googlegroups.com
Anyone knows (or might someone who does know) something about this?

Wolfram Gürlich

unread,
Jul 8, 2013, 5:42:51 AM7/8/13
to google-a...@googlegroups.com
AFAIK forward secrecy is the only available option with all Google services including custom domains. At least it says it uses "ECDHE_RCA" when you look at the SSL connection info.

Thomas Schranz

unread,
Jul 8, 2013, 9:04:53 PM7/8/13
to google-a...@googlegroups.com
Thanks a lot for your reply Wolfram. It indeed looks like all custom domains on app engine support forward secrecy now:

as far as I understand this was not the case at the time I posted to the group but I'm pretty happy about this & hope it stays like that :)

Thomas Schranz

unread,
Sep 17, 2013, 5:41:17 AM9/17/13
to google-a...@googlegroups.com
It looks like using custom domains on app engine are no longer protected by TLS forward secrecy:


Am I reading the ssllabs results the wrong way or did the behaviour change?
I just checked the results with an appspot domain now as well and it also says 'forward secrecy: NO'

Can anyone confirm?

Thomas Schranz

unread,
Sep 17, 2013, 6:11:52 AM9/17/13
to google-a...@googlegroups.com
Just wanted to update that there indeed still is support for forward secrecy for some browsers, but not for all that would support it,
that's why the ssllabs report isn't "green" regarding forward secrecy (which it used to be earlier iirc => maybe they've made the test stricter).

Any input on this would be highly appreciated as we as customers who host on app engine can't do anything about it (improve the situation) from what I understand.
Reply all
Reply to author
Forward
0 new messages