I kind of wish they wouldn't just hand out an A+ that easily. There are clear areas of improvement that the sub-scores call out (90 in both Key Exchange and Cipher Suite). They see the HSTS and grant the A+ when there is clearly improvement that can be made. In my mind, an A+ should be reserved for an SSL/TLS implementation that cannot reasonably be improved upon given the current state of the industry. To improve yo…
I'll do some research around 4096 bit key support. I'm also checking out OCSP stapling.
Edit: precursory investigations show 4096 bit keys generally good to go with a few exceptions, eg AWS CloudFront:http://docs.aws.amazon.com/AmazonCloudFront/latest/Developer...