From de2456c0c419ad61933da124c037a21900c06545 Mon Sep 17 00:00:00 2001 From: Disassembler Date: Thu, 31 Aug 2017 19:45:20 +0200 Subject: [PATCH] Remove DH param, use only elliptic crypto --- basic/etc/nginx/sites-available/default | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/basic/etc/nginx/sites-available/default b/basic/etc/nginx/sites-available/default index c26e69c..1302fdc 100644 --- a/basic/etc/nginx/sites-available/default +++ b/basic/etc/nginx/sites-available/default @@ -1,7 +1,7 @@ server { listen 80; listen [::]:80; - return 301 https://\$host\$request_uri; + return 301 https://$host$request_uri; } server { @@ -11,8 +11,7 @@ server { ssl_certificate /etc/ssl/certs/services.pem; ssl_certificate_key /etc/ssl/private/services.key; ssl_protocols TLSv1.2; - ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS'; - ssl_dhparam /etc/ssl/dhparam.pem; + ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256'; ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:1m; ssl_session_timeout 1d;