Skip to content

Commit 63018e1

Browse files
author
Keith Morgan
committed
Changed ssl_protocols to use only TLS SSL ciphers.
1 parent e1b117e commit 63018e1

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

nginx.conf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -100,8 +100,8 @@ http {
100100
## for crufty clients.
101101
ssl_ciphers ECDH+aRSA+AESGCM:ECDH+aRSA+SHA384:ECDH+aRSA+SHA256:ECDH:EDH+CAMELLIA:EDH+aRSA:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA;
102102

103-
## No SSL2 support. Legacy support of SSLv3.
104-
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;
103+
## Enable TLS only. No SSL support.
104+
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
105105

106106
## Pregenerated Diffie-Hellman parameters.
107107
ssl_dhparam /etc/nginx/dh_param.pem;

0 commit comments

Comments
 (0)