File tree Expand file tree Collapse file tree 2 files changed +7
-3
lines changed Expand file tree Collapse file tree 2 files changed +7
-3
lines changed Original file line number Diff line number Diff line change @@ -104,9 +104,9 @@ CustomLog /proc/self/fd/1 dockerlog
104
104
BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
105
105
106
106
## SSL Hardening
107
- SSLProtocol all -SSLv2 -SSLv3
107
+ SSLProtocol All -SSLv2 -SSLv3
108
108
SSLHonorCipherOrder on
109
- SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS"
110
109
SSLCompression off
110
+ SSLCipherSuite 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA'
111
111
112
112
</VirtualHost>
Original file line number Diff line number Diff line change @@ -50,7 +50,11 @@ server {
50
50
root "<DOCUMENT_ROOT>";
51
51
index <DOCUMENT_INDEX>;
52
52
53
- ssl on;
53
+ ssl on;
54
+ ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive
55
+ ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';
56
+ ssl_prefer_server_ciphers on;
57
+
54
58
ssl_certificate /etc/nginx/ssl/server.crt;
55
59
ssl_certificate_key /etc/nginx/ssl/server.key;
56
60
You can’t perform that action at this time.
0 commit comments