Advertisement
iarmin

nginx SSL - SSLLAbs A

Jul 20th, 2016
164
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 0.63 KB | None | 0 0
  1. # before than please generate a 2048 bit DHPARAM: openssl dhparam -out /etc/nginx/dhparam.pem 2048
  2. #
  3.  
  4. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  5. ssl_prefer_server_ciphers on;
  6. ssl_ciphers EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA512:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:ECDH+AESGCM:ECDH+AES256:DH+AESGCM:DH+AES256:RSA+AESGCM:!aNULL:!eNULL:!LOW:!RC4:3DES:!MD5:!EXP:!PSK:!SRP:!DSS;
  7.  
  8. ssl_session_cache shared:TLS:20m;
  9. ssl_session_cache shared:SSL:20m;
  10. ssl_session_cache shared:ssl_session_cache:20m;
  11.  
  12. ssl_session_timeout 180m;
  13.  
  14. # OCSP stapling
  15. ssl_stapling on;
  16. ssl_stapling_verify on;
  17.  
  18. ssl_dhparam /etc/nginx/dhparam.pem;
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement