Advertisement
Guest User

Untitled

a guest
Jun 29th, 2018
176
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.47 KB | None | 0 0
  1. ssl_certificate /etc/letsencrypt/live/thijs365.com/fullchain.pem;
  2. ssl_certificate_key /etc/letsencrypt/live/thijs365.com/privkey.pem;
  3. keepalive_timeout 70;
  4. ssl_protocols TLSv1.2 TLSv1.3;
  5. ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
  6. #ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256';
  7. ssl_prefer_server_ciphers on;
  8. ssl_session_cache shared:SSL:10m;
  9. ssl_dhparam /etc/nginx/certs/dhparam.pem;
  10. ssl_ecdh_curve secp384r1;
  11. ssl_session_cache shared:SSL:10m;
  12. ssl_session_tickets off;
  13. ssl_session_timeout 10m;
  14. ssl_stapling on;
  15. ssl_stapling_verify on;
  16. resolver 1.1.1.1 1.0.0.1 valid=300s;
  17. resolver_timeout 5s;
  18.  
  19. #Security headers
  20. add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
  21. #add_header Content-Security-Policy "default-src 'self' *.thijs365.com:443/* fonts.googleapis.com *.gstatic.com script-src data:self;";
  22. add_header X-Xss-Protection "1; mode=block" always;
  23. add_header X-Content-Type-Options "nosniff" always;
  24. add_header Referrer-Policy no-referrer;
  25. add_header X-Frame-Options "ALLOW-FROM https://thijs365.com/" always;
  26. #add_header X-Frame-Options "SAMEORIGIN" always;
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement