Skip to content

Instantly share code, notes, and snippets.

@hungmi
Last active August 29, 2018 01:21
Show Gist options
  • Select an option

  • Save hungmi/00c82c8490eb13155cd457849b75a00b to your computer and use it in GitHub Desktop.

Select an option

Save hungmi/00c82c8490eb13155cd457849b75a00b to your computer and use it in GitHub Desktop.

Revisions

  1. hungmi revised this gist Aug 29, 2018. 1 changed file with 4 additions and 1 deletion.
    5 changes: 4 additions & 1 deletion options-ssl-nginx.conf
    Original file line number Diff line number Diff line change
    @@ -1,7 +1,10 @@
    # /etc/letsencrypt/options-ssl-nginx.conf
    ssl_session_timeout 5m;
    ssl_session_cache shared:SSL:9m;
    ssl_session_cache shared:SSL:50m;
    ssl_session_timeout 1440m;
    ssl_session_cache shared:ssl_session_cache:10m;
    ssl_session_tickets off;

    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_prefer_server_ciphers on;
    ssl_ciphers 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx';
  2. hungmi revised this gist Aug 21, 2018. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion options-ssl-nginx.conf
    Original file line number Diff line number Diff line change
    @@ -4,7 +4,7 @@ ssl_session_cache shared:SSL:9m;
    ssl_session_cache shared:ssl_session_cache:10m;
    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_prefer_server_ciphers on;
    ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA';
    ssl_ciphers 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx';

    # 請注意此行可能會跟 /etc/nginx/sites-available/DomainName 裡面的設定重複
    ssl_dhparam /etc/nginx/ssl/DomainName/dhparams.pem;
  3. hungmi revised this gist Aug 21, 2018. 1 changed file with 2 additions and 0 deletions.
    2 changes: 2 additions & 0 deletions options-ssl-nginx.conf
    Original file line number Diff line number Diff line change
    @@ -5,6 +5,8 @@ ssl_session_cache shared:ssl_session_cache:10m;
    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_prefer_server_ciphers on;
    ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA';

    # 請注意此行可能會跟 /etc/nginx/sites-available/DomainName 裡面的設定重複
    ssl_dhparam /etc/nginx/ssl/DomainName/dhparams.pem;
    ssl_stapling on;
    ssl_stapling_verify on;
  4. hungmi revised this gist Jun 17, 2017. 1 changed file with 1 addition and 0 deletions.
    1 change: 1 addition & 0 deletions options-ssl-nginx.conf
    Original file line number Diff line number Diff line change
    @@ -1,3 +1,4 @@
    # /etc/letsencrypt/options-ssl-nginx.conf
    ssl_session_timeout 5m;
    ssl_session_cache shared:SSL:9m;
    ssl_session_cache shared:ssl_session_cache:10m;
  5. hungmi created this gist Jun 17, 2017.
    9 changes: 9 additions & 0 deletions options-ssl-nginx.conf
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,9 @@
    ssl_session_timeout 5m;
    ssl_session_cache shared:SSL:9m;
    ssl_session_cache shared:ssl_session_cache:10m;
    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_prefer_server_ciphers on;
    ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA';
    ssl_dhparam /etc/nginx/ssl/DomainName/dhparams.pem;
    ssl_stapling on;
    ssl_stapling_verify on;