Checks

Weak TLS cipher negotiated

The server selected a cipher whose name contains RC4, DES, NULL, EXPORT, ANON, or MD5.

Why it matters

Those ciphers do not provide modern confidentiality or integrity.

What to do

Disable them and prefer AEAD suites such as AES-GCM or ChaCha20-Poly1305.

Reference

Certificate validity, protocol version, and cipher choice determine TLS trust and strength.

Mozilla SSL Configuration Generator