Advertisement
METAJIJI

nginx _ssl_pfs.conf

Feb 4th, 2016
103
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Nginx 1.65 KB | None | 0 0
  1. # Enable ssl.
  2. ssl on;
  3. ssl_certificate /etc/ssl/mail.univers.su/mail.univers.su.bundle.pem;
  4. ssl_client_certificate /etc/ssl/mail.univers.su/intermediate.pem;
  5. ssl_certificate_key /etc/ssl/mail.univers.su/mail.univers.su.key;
  6.  
  7. # Enable only actual protocols and ciphers.
  8. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  9.  
  10. # Minimal worked like ssllab without weak RC4.
  11. ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA256:EDH-RSA-DES-CBC3-SHA:DES-CBC3-SHA:!aNULL:!eNULL:!MEDIUM:!LOW:!DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED';
  12.  
  13. # Exclude BEAST-attack CVE-2011-3389.
  14. ssl_prefer_server_ciphers on;
  15.  
  16. # Enable session SSL handshake cache.
  17. ssl_session_cache shared:SSL:10m;
  18. ssl_session_timeout 10m;
  19.  
  20. # Add HTTP-header, that inform clients that the server supports only https protocol.
  21. add_header Strict-Transport-Security "max-age=31536000;";
  22.  
  23. # Enable OCSP-response.
  24. # For test it worked: openssl s_client -connect mail.univers.su:443 -tlsextdebug -status | grep OCSP
  25. resolver 8.8.8.8 8.8.4.4 valid=600s; resolver_timeout 15s;
  26. ssl_stapling on;
  27. ssl_stapling_verify on;
  28. ssl_trusted_certificate /etc/ssl/mail.univers.su/intermediate.pem;
  29.  
  30. # Diffie-Hellman parameter for DHE ciphersuites, recommended 2048 bits
  31. # Increase security DH-cipher increase up to 4096. !!!ONLY FOR Admin Management Interfaces!!!
  32. # openssl dhparam -outform PEM -out dhparam4096.pem 4096
  33. #ssl_dhparam /etc/ssl/mail.univers.su/dhparam1024.pem;
  34. #ssl_ecdh_curve secp384r1;
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement