- no IPv6 address for the webserver
- no DNSSEC
- no RPKI ROA for webserver BGP routes
- use of TLS 1.0 and no TLS 1.3
- use of insecure* ciphers
- CSP with 'unsafe-inline' in script-src
When I see TLS 1.0 and no TLS 1.3, I assume there is a bit of legacy openssl or at least the configuration of it. Probably wise to update the config since modern browsers don't support TLS 1.0.
* based on NCSC-NL: https://english.ncsc.nl/publications/publications/2021/janua...