From 2677e6fd87cc1dc3c807b5c1e5c218b1edfc467b Mon Sep 17 00:00:00 2001 From: Edwin Lyon <53972157+practical-engelbart@users.noreply.github.com> Date: Wed, 16 Sep 2020 20:49:07 -0700 Subject: [PATCH] Create ssl.conf --- nginx/snippets/ssl.conf | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 nginx/snippets/ssl.conf diff --git a/nginx/snippets/ssl.conf b/nginx/snippets/ssl.conf new file mode 100644 index 0000000..04aa848 --- /dev/null +++ b/nginx/snippets/ssl.conf @@ -0,0 +1,8 @@ +ssl_session_cache shared:le_nginx_SSL:10m; +ssl_session_timeout 1440m; +ssl_session_tickets off; + +ssl_protocols TLSv1.2 TLSv1.3; +ssl_prefer_server_ciphers off; + +ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA";