From 635a20981838410324f56993f256857942706378 Mon Sep 17 00:00:00 2001 From: classabbyamp Date: Sat, 19 Jul 2025 09:27:33 -0400 Subject: [PATCH] services/pkg/nginx: update ssl conf based on recommendations from mozilla https://ssl-config.mozilla.org/#server=nginx&version=1.28.0&config=intermediate&openssl=3.5.0&hsts=false&guideline=5.7 --- services/pkg/nginx/ssl.conf | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/services/pkg/nginx/ssl.conf b/services/pkg/nginx/ssl.conf index 133a06e8..9ecfa145 100644 --- a/services/pkg/nginx/ssl.conf +++ b/services/pkg/nginx/ssl.conf @@ -7,7 +7,8 @@ ssl_dhparam /etc/nginx/dhparam.pem; # intermediate configuration ssl_protocols TLSv1.2 TLSv1.3; -ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; +ssl_ecdh_curve X25519:prime256v1:secp384r1; +ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305; ssl_prefer_server_ciphers off; # OCSP stapling