File tree 2 files changed +5
-5
lines changed
2 files changed +5
-5
lines changed Original file line number Diff line number Diff line change 1
1
listen 192.168.250.2:443 ssl http2;
2
2
3
3
ssl_session_cache shared:SSL:10m;
4
- ssl_session_timeout 5m ;
4
+ ssl_session_timeout 4h ;
5
5
ssl_session_tickets off;
6
6
ssl_buffer_size 1400;
7
7
8
8
ssl_protocols TLSv1.3 TLSv1.2;
9
- ssl_ciphers "TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256: ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384: ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-POLY1305: ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256";
9
+ ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305 :DHE-RSA-AES128-GCM-SHA256";
10
10
11
11
ssl_prefer_server_ciphers on;
12
12
13
13
ssl_ecdh_curve X25519:secp521r1:secp384r1:prime256v1;
14
14
15
- # ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;
15
+ ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;
Original file line number Diff line number Diff line change @@ -6,10 +6,10 @@ ssl_session_tickets off;
6
6
ssl_buffer_size 1400;
7
7
8
8
ssl_protocols TLSv1.3 TLSv1.2;
9
- ssl_ciphers "TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256: ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384: ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-POLY1305: ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256";
9
+ ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305 :DHE-RSA-AES128-GCM-SHA256";
10
10
11
11
ssl_prefer_server_ciphers on;
12
12
13
13
ssl_ecdh_curve X25519:secp521r1:secp384r1:prime256v1;
14
14
15
- # ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;
15
+ ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;
You can’t perform that action at this time.
0 commit comments