Updated TLS cipher suites

Improvement•

We've updated the TLS 1.2 cipher suites on the edge network.

HTTPS redirects now follow Mozilla's Intermediate profile, which matches NCSC-NL guidance: AES-GCM and ChaCha20-Poly1305 only. CBC and SHA-1 MAC suites are no longer offered. TLS 1.3 is unchanged.

Your redirects work the same way. Current browsers and clients are unaffected. We still hold an A+ rating from Qualys SSL Labs on every plan. Read more in the automatic HTTPS article.