Evaluation of SSL/TLS Configuration in Academic Information Systems: A Case Study
Keywords:
SSL/TLS, web security, configuration analysis, academic information systems, cybersecurityAbstract
The security of web-based academic information systems has become increasingly critical as sensitive data is continuously exchanged over public networks. One of the primary mechanisms for securing such communication is the implementation of Secure Sockets Layer (SSL) and Transport Layer Security (TLS). However, the effectiveness of these protocols is highly dependent on proper configuration rather than mere adoption. Misconfigurations can introduce significant vulnerabilities, even in systems that utilize modern encryption standards. This study evaluates the SSL/TLS implementation of an academic information system using a configuration-based security assessment approach. The analysis focuses on key parameters, including protocol support, certificate validity, key exchange strength, cipher strength, and forward secrecy. Data is obtained through an external assessment using the Qualys SSL Labs platform and is analyzed descriptively and comparatively against established security best practices. The results indicate that the system has implemented TLS 1.3 and employs strong cryptographic algorithms, achieving an overall security rating of B. Despite these strengths, the absence of consistent forward secrecy and suboptimal key exchange configurations limit the system’s overall security posture. These findings highlight that while the system provides adequate baseline protection, it remains vulnerable to advanced threats such as retrospective decryption and downgrade attacks.
Downloads
References
Acar, Y., Fahl, S., & Mazurek, M. L. (2016). You Are Not Your Developer, Either: A Research Agenda for Usable Security and Privacy Research Beyond End Users. https://doi.org/10.1109/SecDev.2016.20
Alashwali, E. S., Szalachowski, P., & Martin, A. (2020). Exploring HTTPS security inconsistencies: A cross-regional perspective. Computers & Security, 97, 101975. https://doi.org/10.1016/j.cose.2020.101975
Albrecht, M. R., Paterson, K. G., & Watson, G. J. (n.d.). Plaintext Recovery Attacks Against SSH.
Altulaihan, E. A., Alismail, A., & Frikha, M. (2023). A Survey on Web Application Penetration Testing. Electronics, 12(5), 1229. https://doi.org/10.3390/electronics12051229
Amann, B., Sommer, R., Vallentin, M., & Hall, S. (2013). No attack necessary: The surprising dynamics of SSL trust relationships. ACM International Conference Proceeding Series, 179–188. https://doi.org/10.1145/2523649.2523665
Beurdouche, B., Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Kohlweiss, M., Pironti, A., Strub, P.-Y., & Zinzindohoue, J. K. (2017). A messy state of the union. Communications of the ACM, 60(2), 99–107. https://doi.org/10.1145/3023357
Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Pironti, A., & Strub, P. Y. (2014). Triple handshakes and cookie cutters: Breaking and fixing authentication over TLS. Proceedings - IEEE Symposium on Security and Privacy, 98–113. https://doi.org/10.1109/SP.2014.14
Calzavara, S., Focardi, R., Squarcina, M., & Tempesta, M. (2018). Surviving the Web. ACM Computing Surveys, 50(1), 1–34. https://doi.org/10.1145/3038923
Clark, J., & van Oorschot, P. C. (2013). SoK: SSL and HTTPS: Revisiting Past Challenges and Evaluating Certificate Trust Model Enhancements. 2013 IEEE Symposium on Security and Privacy, 511–525. https://doi.org/10.1109/SP.2013.41
De Ruiter, J., & Poll, E. (n.d.). Open access to the Proceedings of the 24th USENIX Security Symposium is sponsored by USENIX Protocol State Fuzzing of TLS Implementations Protocol state fuzzing of TLS implementations. Retrieved https://www.ssllabs.com/ssltest/
Durumeric, Z., Ma, Z., Springall, D., Barnes, R., Sullivan, N., Bursztein, E., Bailey, M., Halderman, J. A., & Paxson, V. (2017). The Security Impact of HTTPS Interception. 24th Annual Network and Distributed System Security Symposium, NDSS 2017. https://doi.org/10.14722/ndss.2017.23456
Holz, R., Amann, J., Mehani, O., Wachs, M., & Kaafar, M. A. (2016). TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic Communication. 23rd Annual Network and Distributed System Security Symposium, NDSS 2016. https://doi.org/10.14722/ndss.2016.23055
Holz, R., Hiller, J., Amann, J., Razaghpanah, A., Jost, T., Vallina-Rodriguez, N., & Hohlfeld, O. (2020). Tracking the deployment of TLS 1.3 on the web. ACM SIGCOMM Computer Communication Review, 50(3), 3–15. https://doi.org/10.1145/3411740.3411742
Hu, Q., Asghar, M. R., & Brownlee, N. (2021). A large-scale analysis of HTTPS deployments: Challenges, solutions, and recommendations. Journal of Computer Security, 29(1), 25–50. https://doi.org/10.3233/JCS-200070
Rescorla, E. (2018). The Transport Layer Security (TLS) Protocol Version 1.3. https://doi.org/10.17487/RFC8446
Sheffer, Y., Saint-Andre, P., & Fossati, T. (2022). Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS). https://doi.org/10.17487/RFC9325
Sherry, J., Lan, C., Popa, R. A., & Ratnasamy, S. (2015). BlindBox. Proceedings of the 2015 ACM Conference on Special Interest Group on Data Communication, 213–226. https://doi.org/10.1145/2785956.2787502
Somorovsky, J. (2016). Systematic Fuzzing and Testing of TLS Libraries. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 1492–1504. https://doi.org/10.1145/2976749.2978411
Vanhoef, M., & Ronen, E. (2020). Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwd. 2020 IEEE Symposium on Security and Privacy (SP), 517–533. https://doi.org/10.1109/SP40000.2020.00031
Zhang, Z., Hamadi, H. Al, Damiani, E., Yeun, C. Y., & Taher, F. (2022). Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research. IEEE Access, 10, 93104–93139. https://doi.org/10.1109/ACCESS.2022.3204051
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Murni Marisma, Ermadi Satriya Wijaya, Mukhlis Prasetyo Aji, Agung Purwo Wicaksono

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
