improve default tls security

This commit is contained in:
thelittlefireman
2021-02-28 23:59:22 +01:00
committed by GitHub
parent d5d699252c
commit 5940f402c7

View File

@@ -2,7 +2,7 @@ listen 0.0.0.0:%HTTPS_PORT% ssl %HTTP2%;
ssl_certificate %HTTPS_CERT%; ssl_certificate %HTTPS_CERT%;
ssl_certificate_key %HTTPS_KEY%; ssl_certificate_key %HTTPS_KEY%;
ssl_protocols %HTTPS_PROTOCOLS%; ssl_protocols %HTTPS_PROTOCOLS%;
ssl_prefer_server_ciphers off; ssl_prefer_server_ciphers on;
ssl_session_tickets off; ssl_session_tickets off;
ssl_session_timeout 1d; ssl_session_timeout 1d;
ssl_session_cache shared:MozSSL:10m; ssl_session_cache shared:MozSSL:10m;