Ubuntu 225 's stock ssl.conf already refuses TLS 1.0 and 1.1, but its SSLCipherSuite HIGH:!aNULL still admits CBC suites. Replace it server-wide with Mozilla's "intermediate" profile, guidelines 6.0 (ssl-config.mozilla.org (https://ssl-config.mozilla.org/ 102 )):
SSLProtocol -all +TLSv1.2 +TLSv1.3
SSLOpenSSLConfCmd Groups X25519MLKEM768:X25519:prime256v1:secp384r1
SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:\
ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:\
ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305
SSLHonorCipherOrder off
SSLSessionTickets offThe cipher list governs TLS 1.2 only, since every TLS 1.3 suite is AEAD. After a2enconf tls-intermediate and a reload, probe one suite at a time, then inspect a live Let's Encrypt 1,144 certificate:
p() { echo | openssl s_client -connect localhost:443 "$@" 2>&1 | grep -E "^(New|Negotiated)"; }
p -tls1_2 -cipher ECDHE-ECDSA-AES256-SHA # a CBC suite: accepted before the change
p -tls1_3
echo | openssl s_client -connect letsencrypt.org:443 2>/dev/null |
openssl x509 -noout -issuer -ocsp_uri -ext crlDistributionPointsNew, (NONE), Cipher is (NONE)
Negotiated TLS1.3 group: X25519MLKEM768
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
issuer=C=US, O=Let's Encrypt, CN=YE2
X509v3 CRL Distribution Points:
Full Name:
URI:http://ye2.c.lencr.org/96.crlThe CBC handshake now fails, and -ocsp_uri printed nothing. Stapling attached a signed OCSP "not revoked" answer to the handshake, but Let's Encrypt dropped OCSP URLs from certificates on 7 May 2025 and shut its responders on 6 August 2025; revocation now uses CRLs. SSLUseStapling on then only logs AH02218 ... no OCSP URI in certificate, so leave it off unless your CA runs a responder. HSTS is HTTPS and HSTS.