# Hardening security for your enterprise

You can configure features and settings to harden security for your enterprise.

## Links

* [Configuring TLS](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/configuring-tls)

  You can configure Transport Layer Security (TLS) on GitHub.com so that you can use a certificate that is signed by a trusted certificate authority.

* [Configuring TLS and SSH ciphers](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/configuring-tls-and-ssh-ciphers)

  You can configure the cipher suites and cryptographic algorithms that GitHub Enterprise Server uses for TLS and SSH connections to meet specific compliance or security requirements.

* [Troubleshooting TLS errors](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/troubleshooting-tls-errors)

  If you run into TLS issues with your appliance, you can take actions to resolve them.

* [Enabling private mode](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/enabling-private-mode)

  In private mode, GitHub Enterprise Server requires every user to sign in to access the installation.

* [Enabling subdomain isolation](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/enabling-subdomain-isolation)

  You can set up subdomain isolation to securely separate user-supplied content from other portions of your GitHub Enterprise Server appliance.

* [Configuring host keys for your instance](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/configuring-host-keys-for-your-instance)

  You can increase the security of GitHub.com by configuring the algorithms that your instance uses to generate and advertise host keys for incoming SSH connections.

* [Configuring SSH connections to your instance](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/configuring-ssh-connections-to-your-instance)

  You can increase the security of GitHub.com by configuring the SSH algorithms that clients can use to establish a connection.

* [Configuring the referrer policy for your enterprise](/en/enterprise-server@3.22/admin/configuring-settings/hardening-security-for-your-enterprise/configuring-the-referrer-policy-for-your-enterprise)

  You can increase the privacy of GitHub.com by configuring the policy for cross-origin requests.

* [/restricting-network-traffic-to-your-enterprise-with-an-ip-allow-list](/en/enterprise-server@3.22/restricting-network-traffic-to-your-enterprise-with-an-ip-allow-list)

* [/restricting-access-to-githubcom-using-a-corporate-proxy](/en/enterprise-server@3.22/restricting-access-to-githubcom-using-a-corporate-proxy)