Skip to content

Commit ae35326

Browse files
committed
update ciphers and enable DH params
- signed-off-by: trimstray <[email protected]>
1 parent 395a06e commit ae35326

File tree

2 files changed

+5
-5
lines changed

2 files changed

+5
-5
lines changed
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
listen 192.168.250.2:443 ssl http2;
22

33
ssl_session_cache shared:SSL:10m;
4-
ssl_session_timeout 5m;
4+
ssl_session_timeout 4h;
55
ssl_session_tickets off;
66
ssl_buffer_size 1400;
77

88
ssl_protocols TLSv1.3 TLSv1.2;
9-
ssl_ciphers "TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256";
9+
ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256";
1010

1111
ssl_prefer_server_ciphers on;
1212

1313
ssl_ecdh_curve X25519:secp521r1:secp384r1:prime256v1;
1414

15-
# ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;
15+
ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;

lib/nginx/master/_listen/localhost/https.conf

+2-2
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ ssl_session_tickets off;
66
ssl_buffer_size 1400;
77

88
ssl_protocols TLSv1.3 TLSv1.2;
9-
ssl_ciphers "TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256";
9+
ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256";
1010

1111
ssl_prefer_server_ciphers on;
1212

1313
ssl_ecdh_curve X25519:secp521r1:secp384r1:prime256v1;
1414

15-
# ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;
15+
ssl_dhparam /etc/nginx/dhparam_4096-with-ds.pem;

0 commit comments

Comments
 (0)